bleeping-computer · Crawled Jul 23, 2026
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
1 IoCs 1 Actors
Read original article ↗
AI Summary
The Chaos ransomware gang is deploying a new Rust-based backdoor named msaRAT that leverages Chrome or Edge browsers to route command-and-control (C2) traffic, evading detection by avoiding direct network connections. The malware uses the Chrome DevTools Protocol to control a headless browser session and establishes encrypted communication via WebRTC through Twilio TURN servers and a Cloudflare Workers endpoint. This dual-layer infrastructure hides the attacker's true C2 server and complicates traceback efforts, while also bypassing firewalls and allowlists by blending with legitimate web traffic.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | is-01-ast[.]ols-img-12[.]workers[.]dev | Details → |
MITRE ATT&CK TTPs 32 techniques
T1001.002 Steganography · Command And Control T1003 OS Credential Dumping · Credential Access T1003.002 Security Account Manager · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1082 System Information Discovery · Discovery T1085 T1085 T1090 Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1132.001 Standard Encoding · Command And Control T1204.002 Malicious File · Execution T1219 Remote Access Software · Command And Control T1486 Data Encrypted for Impact · Impact T1543.003 Windows Service · Persistence T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1566.002 Spearphishing Link · Initial Access T1573.001 Symmetric Cryptography · Command And Control T1574.002 DLL Side-Loading · Persistence T1588 Obtain Capabilities · Resource Development