securityaffairs.com 7/23/2026, 6:51:02 PM · external

Chaos ransomware hides C2 traffic in Chrome using msaRAT

Chaos ransomware hides C2 traffic in Chrome using msaRAT
Developing story malware 2 articles tracked
Chaos ransomware uses msaRAT to hide C2 traffic in Chrome
CyberSIXT Evidence Panel

CHAOS ransomware has deployed a remote access trojan (RAT) called msaRAT, designed to evade network detection by routing command-and-control (C2) traffic through Chrome or Edge using the Chrome DevTools Protocol. The malware makes no direct network connections; instead, it uses the browser to manage all communication, making it difficult for defenders to detect malicious activities.

After infection, msaRAT runs in headless mode, injecting JavaScript into the browser to perform its functions while avoiding detection. The communication is encrypted and often appears as legitimate traffic, thus complicating detection efforts. Key indicators for detection include unusual browser process activity and specific user-agent strings. Cisco Talos has published signatures and detection rules to help identify msaRAT.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline