Skip to content
Chaos ransomware uses browser

Chaos ransomware uses browser

Feeds.4Sysops IT News July 23, 2026

The Chaos ransomware group has deployed a new Rust-based remote access trojan, msaRAT, which disguises command-and-control traffic by routing it through legitimate web browsers. By launching Chrome or Microsoft Edge in headless mode with remote debugging enabled, the malware utilizes the Chrome DevTools Protocol to manage communications. This design ensures that all external network activity appears to originate from standard browser processes rather than malicious infrastructure. Source

Extracted Entities

Attack Types (1)

Malware (1)

MITRE ATT&CK (1)

Platforms (1)

Ransomware Groups (1)