Chaos Ransomware Deploys msaRAT for Covert C2 via Browsers

Chaos Ransomware Deploys msaRAT for Covert C2 via Browsers

First seen 23 Jul 2026, 14:24 UTC Blog.TalosintelligenceFeeds2.FeedburnerThehackernewsFeeds.4Sysops 80% similarity 66.5

Article Content

Browse articles
ThreatCluster

The Chaos ransomware group has introduced a new Rust-based remote access trojan (RAT) named msaRAT, which utilizes web browsers to conceal command-and-control (C2) traffic. This malware operates by launching Chrome or Microsoft Edge in headless mode, using the Chrome DevTools Protocol to manage communications, ensuring that all network activity appears legitimate. The RAT is designed to be stealthy, leveraging browser processes to evade detection by security systems. Initial access is typically gained through spam emails and vishing tactics, followed by the deployment of the RAT to establish persistent access. The malware downloads an MSI file that masquerades as a Windows update, which then executes the RAT payload. The use of legitimate browser processes for C2 communications significantly complicates detection efforts. The Chaos group is known for targeting large organizations and employing double extortion tactics. The current status indicates ongoing threats as the group continues to evolve its methods.

Key Points: • Chaos ransomware's msaRAT uses browsers for covert C2 communications. • The RAT is deployed via a disguised MSI file that mimics a Windows update. • Initial access is gained through spam emails and vishing tactics.

ThreatCluster AI

Timeline

2025-02-01
Chaos ransomware group activity confirmed
Chaos ransomware's operations were first identified, targeting large organizations with double extortion tactics.
Blog.Talosintelligence
2026-07-23
msaRAT identified by Cisco Talos
Cisco Talos reported the discovery of msaRAT, a new Rust-based RAT used by the Chaos ransomware group.
Blog.Talosintelligence
2026-07-23
Browser-based C2 traffic evasion reported
msaRAT routes C2 traffic through legitimate web browsers, complicating detection efforts.
Feeds.4Sysops
2026-07-23
C2 traffic managed via Chrome DevTools Protocol
The RAT controls browser instances using the Chrome DevTools Protocol to manage communications.
Feeds2.Feedburner

Community

Browse all →