Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Jul 23, 2026 - 14:00
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both browsers. The browser then carries the command-and-control traffic over a WebRTC channel. Once installed, the RAT process keeps all of … More

The post Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process appeared first on Help Net Security.