CHAOS ransomware has deployed a remote access trojan (RAT) called msaRAT, designed to evade network detection by routing command-and-control (C2) traffic through Chrome or Edge using the Chrome DevTools Protocol. The malware makes no direct network connections; instead, it uses the browser to manage all communication, making it difficult for defenders to detect malicious activities.
After infection, msaRAT runs in headless mode, injecting JavaScript into the browser to perform its functions while avoiding detection. The communication is encrypted and often appears as legitimate traffic, thus complicating detection efforts. Key indicators for detection include unusual browser process activity and specific user-agent strings. Cisco Talos has published signatures and detection rules to help identify msaRAT.