← All briefs
Brief·3 sources23 Jul 2026

msaRAT Deploys Browser-Hijacked C2 Channel For Chaos Ransomware

ransomwareransomware-as-a-servicemalwarecommand-and-controlcybercrime

Summary

msaRAT is a Rust-based remote access trojan newly attributed to the Chaos ransomware group, disclosed by Cisco Talos on 23 July 2026. The implant represents a significant operational security innovation: rather than establishing outbound network connections of its own, it hijacks the victim's installed Chrome or Edge browser — running it in headless mode — and routes all command-and-control (C2) traffic through the browser process via the Chrome DevTools Protocol (CDP).

The technique renders the implant highly evasive. Because the process communicates only with 127.0.0.1 (localhost) and all external traffic originates from a legitimate browser binary, conventional network-based detection that flags unusual outbound connections is largely bypassed. WebRTC over TURN is additionally used to conceal the attacker's true IP address from the victim's environment.

msaRAT was recovered from a compromised Windows machine ahead of ransomware encryptor deployment, indicating it is used in the pre-encryption staging phase of a Chaos intrusion. The implant enables arbitrary command execution and almost certainly serves as the primary post-compromise persistence and reconnaissance tool before the final ransomware payload is released.

Timeline

  1. 23 July 2026
    Cisco Talos publishes msaRAT technical disclosure
    Cisco Talos releases detailed analysis of msaRAT, a Rust-based RAT attributed to the Chaos ransomware group, recovered from a compromised Windows machine ahead of encryptor deployment.
  2. 23 July 2026
    SecurityAffairs and The Hacker News report on msaRAT browser-based C2 technique
    Industry reporting amplifies the Cisco Talos disclosure, highlighting msaRAT's use of the Chrome DevTools Protocol and headless browser hijacking to route C2 traffic covertly.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs, and response recommendations — available inside the Deltabridge platform.

msaRAT Deploys Browser-Hijacked C2 Channel For Chaos Ransomware — Deltabridge