As cited
Copy frozen at (site build).
ransomware
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos discovered msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that establishes command-and-control communications exclusively through Chrome DevTools Protocol rather than direct network connections. The malware is delivered via a malicious MSI installer disguised as a Windows update and leverages the browser, Cloudflare Workers, and Twilio TURN relays to create a covert WebRTC DataChannel for C2 communications. Chaos is a ransomware-as-a-service group active since February 2025 that uses phishing, vishing, and legitimate tools for post-compromise activities before deploying encryption.
Why it matters: Organizations targeted by Chaos ransomware need to detect and block msaRAT to prevent covert C2 establishment; security teams should monitor for suspicious MSI installations, Chrome DevTools Protocol activity, and WebRTC connections that bypass traditional network-based defenses.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos discovered msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that establishes command-and-control communications exclusively through Chrome DevTools Protocol rather than direct network connections. The malware is delivered via a malicious MSI installer disguised as a Windows update and leverages the browser, Cloudflare Workers, and Twilio TURN relays to create a covert WebRTC DataChannel for C2 communications. Chaos is a ransomware-as-a-service group active since February 2025 that uses phishing, vishing, and legitimate tools for post-compromise activities before deploying encryption.
Why it matters: Organizations targeted by Chaos ransomware need to detect and block msaRAT to prevent covert C2 establishment; security teams should monitor for suspicious MSI installations, Chrome DevTools Protocol activity, and WebRTC connections that bypass traditional network-based defenses.
- Source published
- First seen by Cybersecurity Tracker