CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3081

As cited

Copy frozen at (site build).

ransomware

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos discovered msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that establishes command-and-control communications exclusively through Chrome DevTools Protocol rather than direct network connections. The malware is delivered via a malicious MSI installer disguised as a Windows update and leverages the browser, Cloudflare Workers, and Twilio TURN relays to create a covert WebRTC DataChannel for C2 communications. Chaos is a ransomware-as-a-service group active since February 2025 that uses phishing, vishing, and legitimate tools for post-compromise activities before deploying encryption.

Why it matters: Organizations targeted by Chaos ransomware need to detect and block msaRAT to prevent covert C2 establishment; security teams should monitor for suspicious MSI installations, Chrome DevTools Protocol activity, and WebRTC connections that bypass traditional network-based defenses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos discovered msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that establishes command-and-control communications exclusively through Chrome DevTools Protocol rather than direct network connections. The malware is delivered via a malicious MSI installer disguised as a Windows update and leverages the browser, Cloudflare Workers, and Twilio TURN relays to create a covert WebRTC DataChannel for C2 communications. Chaos is a ransomware-as-a-service group active since February 2025 that uses phishing, vishing, and legitimate tools for post-compromise activities before deploying encryption.

Why it matters: Organizations targeted by Chaos ransomware need to detect and block msaRAT to prevent covert C2 establishment; security teams should monitor for suspicious MSI installations, Chrome DevTools Protocol activity, and WebRTC connections that bypass traditional network-based defenses.

VendorsCiscoCloudflareGoogleMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary