Skip to content
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Feeds2.Feedburner Mirko Zorz July 23, 2026

Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both browsers. The browser then carries the command-and-control traffic over a WebRTC channel. Once installed, the RAT process keeps all of … More →

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (1)

Ransomware Groups (1)