Chaos Ransomware Deploys msaRAT to Evade Detection via Browsers

Chaos Ransomware Deploys msaRAT to Evade Detection via Browsers

First seen 23 Jul 2026, 14:24 UTC Blog.TalosintelligenceFeeds2.FeedburnerThehackernewsFeeds.4SysopsCybersecuritynews+1 82% similarity 69.5

Article Content

Browse articles
ThreatCluster

The Chaos ransomware group has introduced a new Rust-based remote access trojan (RAT) named msaRAT, which disguises command-and-control (C2) traffic through legitimate web browsers like Chrome and Microsoft Edge. By utilizing the Chrome DevTools Protocol, msaRAT can manage communications while appearing as standard browser activity, thus evading network detection. The malware is executed after an initial compromise, typically through phishing methods such as spam emails or vishing. Once installed, msaRAT establishes a covert C2 channel, allowing attackers to send commands and exfiltrate data without raising alarms. This new tactic highlights the evolving sophistication of ransomware groups in leveraging existing software to mask malicious activities. Cisco Talos has confirmed the existence of this RAT and provided details on its operation and capabilities.

Key Points: • Chaos ransomware's msaRAT uses browsers to hide C2 traffic, enhancing stealth. • The RAT is executed via a compromised MSI file that mimics a Windows update. • Initial access often occurs through phishing tactics like spam emails and vishing.

ThreatCluster AI

Timeline

2025-02-01
Chaos ransomware group confirmed active
The Chaos ransomware group was first confirmed to be active in February 2025, targeting large organizations.
Blog.Talosintelligence
2026-07-23
msaRAT identified by Cisco Talos
Cisco Talos disclosed the msaRAT, detailing its use of Chrome and Edge for C2 traffic routing.
Blog.Talosintelligence
2026-07-23
Browser-based C2 traffic confirmed
The RAT utilizes the Chrome DevTools Protocol to manage C2 communications, appearing as legitimate browser activity.
Feeds.4Sysops
2026-07-23
RAT executed via MSI file
The malware is executed by downloading an MSI file disguised as a Windows update, which installs the RAT on the victim's machine.
Blog.Talosintelligence

Community

Browse all →