All incidents

Chaos ransomware uses msaRAT to hide C2 traffic in Chrome

malwareopenJul 23, 2026 — Jul 23, 2026
Chaos ransomware uses msaRAT to hide C2 traffic in Chrome

CHAOS ransomware has added a new stealth layer by using a custom remote access trojan called msaRAT to route its command‑and‑control traffic through Chrome or Edge browsers, according to recent analysis.

The trojan launches the browser in headless mode, injects JavaScript and then uses the Chrome DevTools Protocol to create an encrypted channel that appears as normal web traffic, as detailed by Cisco Talos.

Because the malware never opens a direct network socket, traditional network‑based detections see only ordinary browser connections, often mimicking legitimate user‑agent strings, which makes the malicious activity blend in with regular browsing.

Cisco Talos first observed the technique in late July 2026 and has released YARA rules and Snort signatures that flag the abnormal process behaviour and specific user‑agent patterns associated with msaRAT, according to its advisory.

Security teams should monitor for headless Chrome or Edge processes that lack a visible window, inspect command‑line arguments for remote‑debugging ports, and correlate those with outbound TLS traffic to unfamiliar domains.

Applying the Talos detection rules, updating endpoint protection platforms and ensuring browser extensions are limited to approved sources can reduce the chance that the trojan gains a foothold.

Intelligence briefing updated Jul 23, 2026

Root sourceblog.talosintelligence.com
Timeline Coverage

Swipe to explore timeline