Feeds2.Feedburner
Chaos Ransomware Deploys msaRAT to Evade Detection via Browsers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Chaos ransomware group has introduced a new Rust-based remote access trojan (RAT) named msaRAT, which disguises command-and-control (C2) traffic through legitimate web browsers like Chrome and Microsoft Edge. By utilizing the Chrome DevTools Protocol, msaRAT can manage communications while appearing as standard browser activity, thus evading network detection. The malware is executed after an initial compromise, typically through phishing methods such as spam emails or vishing. Once installed, msaRAT establishes a covert C2 channel, allowing attackers to send commands and exfiltrate data without raising alarms. This new tactic highlights the evolving sophistication of ransomware groups in leveraging existing software to mask malicious activities. Cisco Talos has confirmed the existence of this RAT and provided details on its operation and capabilities.
Key Points: • Chaos ransomware's msaRAT uses browsers to hide C2 traffic, enhancing stealth. • The RAT is executed via a compromised MSI file that mimics a Windows update. • Initial access often occurs through phishing tactics like spam emails and vishing.