< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-23T18:41:09+05:30

Chaos Ransomware Leverages msaRAT for C2 Traffic Obfuscation via Headless Browsers

Chaos Ransomware employs msaRAT to obfuscate C2 traffic by routing it through headless Chrome/Edge browsers using WebRTC and Twilio's TURN service, evading traditional network monitoring. The technique leverages browser automation and encrypted channels to maintain stealthy command-and-control communication.

The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.

The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge in headless mode and drives the browser

Read original article

*** END OF TRANSMISSION ***