bleeping-computer · Crawled Jul 23, 2026

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

1 IoCs 1 Actors
Read original article ↗

AI Summary

The Chaos ransomware gang is deploying a new Rust-based backdoor named msaRAT that leverages Chrome or Edge browsers to route command-and-control (C2) traffic, evading detection by avoiding direct network connections. The malware uses the Chrome DevTools Protocol to control a headless browser session and establishes encrypted communication via WebRTC through Twilio TURN servers and a Cloudflare Workers endpoint. This dual-layer infrastructure hides the attacker's true C2 server and complicates traceback efforts, while also bypassing firewalls and allowlists by blending with legitimate web traffic.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Domain is-01-ast[.]ols-img-12[.]workers[.]dev Details →

MITRE ATT&CK TTPs 16 techniques