Feeds2.Feedburner
Chaos Ransomware Deploys msaRAT for Covert C2 via Browsers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Chaos ransomware group has introduced a new Rust-based remote access trojan (RAT) named msaRAT, which utilizes web browsers to conceal command-and-control (C2) traffic. This malware operates by launching Chrome or Microsoft Edge in headless mode, using the Chrome DevTools Protocol to manage communications, ensuring that all network activity appears legitimate. The RAT is designed to be stealthy, leveraging browser processes to evade detection by security systems. Initial access is typically gained through spam emails and vishing tactics, followed by the deployment of the RAT to establish persistent access. The malware downloads an MSI file that masquerades as a Windows update, which then executes the RAT payload. The use of legitimate browser processes for C2 communications significantly complicates detection efforts. The Chaos group is known for targeting large organizations and employing double extortion tactics. The current status indicates ongoing threats as the group continues to evolve its methods.
Key Points: • Chaos ransomware's msaRAT uses browsers for covert C2 communications. • The RAT is deployed via a disguised MSI file that mimics a Windows update. • Initial access is gained through spam emails and vishing tactics.