As cited
Copy frozen at (site build).
threat intel
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Chaos ransomware operators deployed a new backdoor called msaRAT that conceals command-and-control traffic by routing it through Chrome or Edge browsers. This technique allows attackers to blend malicious communications with legitimate browser traffic, making detection more difficult.
Why it matters: Organizations targeted by Chaos ransomware need to monitor for msaRAT infections and unusual browser-based C2 connections, as this malware enables attackers to establish persistent remote access while evading network defenses.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Chaos ransomware operators deployed a new backdoor called msaRAT that conceals command-and-control traffic by routing it through Chrome or Edge browsers. This technique allows attackers to blend malicious communications with legitimate browser traffic, making detection more difficult.
Why it matters: Organizations targeted by Chaos ransomware need to monitor for msaRAT infections and unusual browser-based C2 connections, as this malware enables attackers to establish persistent remote access while evading network defenses.
- Source published
- First seen by Cybersecurity Tracker