bleeping-computer · Crawled Jul 23, 2026
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
1 IoCs 1 Actors
Read original article ↗
AI Summary
The Chaos ransomware gang is deploying a new Rust-based backdoor named msaRAT that leverages Chrome or Edge browsers to route command-and-control (C2) traffic, evading detection by avoiding direct network connections. The malware uses the Chrome DevTools Protocol to control a headless browser session and establishes encrypted communication via WebRTC through Twilio TURN servers and a Cloudflare Workers endpoint. This dual-layer infrastructure hides the attacker's true C2 server and complicates traceback efforts, while also bypassing firewalls and allowlists by blending with legitimate web traffic.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | is-01-ast[.]ols-img-12[.]workers[.]dev | Details → |
MITRE ATT&CK TTPs 16 techniques
T1003 OS Credential Dumping · Credential Access T1027 Obfuscated Files or Information · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1071.001 Web Protocols · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1219 Remote Access Software · Command And Control T1566 Phishing · Initial Access T1573.001 Symmetric Cryptography · Command And Control T1588 Obtain Capabilities · Resource Development