256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge - The Hacker News

Share
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge - The Hacker News
Image · Internet

What the report says

The Hacker News reported that Cisco Talos has detailed a Rust-based remote access trojan, dubbed msaRAT, used in activity linked to the Chaos ransomware group. According to the July 23 report, Talos found the implant on a compromised Windows system before ransomware encryption took place. The malware’s notable feature is that it does not directly make outbound command-and-control connections; instead, it communicates locally and uses a headless Chrome or Edge browser to send traffic outward.

The report says msaRAT launches Chrome or Edge with Chrome DevTools Protocol access enabled, then injects JavaScript to create a WebRTC data channel. Signaling was routed through a Cloudflare Worker, while the live channel was relayed through Twilio’s TURN service. That means network defenders may see traffic that appears to come from a legitimate browser connecting to common cloud and communications services, while the attacker’s infrastructure remains hidden from direct view. The traffic also includes an additional encryption layer inside the browser’s own WebRTC encryption.

Talos said the implant was delivered via a curl download of an MSI file presented as a Windows update. A custom installer action loaded an embedded DLL into memory, where the Rust implant ran. The report did not identify the victim, state how the initial compromise occurred, or say how widely msaRAT has been deployed.

The case matters because it highlights a post-compromise technique that does not rely on a browser vulnerability and may be difficult to block with simple network rules. The Hacker News said Talos recommended hunting for unusual headless Chrome or Edge launches, especially when started by installers, services or other non-interactive processes, and correlating those launches with loopback debugging traffic and outbound WebRTC activity.

Read the full report at Internet →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting