The Chaos ransomware group has deployed a new Rust-based remote access trojan, msaRAT, which disguises command-and-control traffic by routing it through legitimate web browsers. By launching Chrome or Microsoft Edge in headless mode with remote debugging enabled, the malware utilizes the Chrome DevTools Protocol to manage communications. This design ensures that all external network activity appears to originate from standard browser processes rather than malicious infrastructure. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
