CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3068

As cited

Copy frozen at (site build).

threat intel

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

Chaos ransomware operators deployed a new backdoor called msaRAT that conceals command-and-control traffic by routing it through Chrome or Edge browsers. This technique allows attackers to blend malicious communications with legitimate browser traffic, making detection more difficult.

Why it matters: Organizations targeted by Chaos ransomware need to monitor for msaRAT infections and unusual browser-based C2 connections, as this malware enables attackers to establish persistent remote access while evading network defenses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

Chaos ransomware operators deployed a new backdoor called msaRAT that conceals command-and-control traffic by routing it through Chrome or Edge browsers. This technique allows attackers to blend malicious communications with legitimate browser traffic, making detection more difficult.

Why it matters: Organizations targeted by Chaos ransomware need to monitor for msaRAT infections and unusual browser-based C2 connections, as this malware enables attackers to establish persistent remote access while evading network defenses.

VendorsCiscoGoogleMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary