msaRAT is a Rust-based remote access trojan newly attributed to the Chaos ransomware group, disclosed by Cisco Talos on 23 July 2026. The implant represents a significant operational security innovation: rather than establishing outbound network connections of its own, it hijacks the victim's installed Chrome or Edge browser — running it in headless mode — and routes all command-and-control (C2) traffic through the browser process via the Chrome DevTools Protocol (CDP).
The technique renders the implant highly evasive. Because the process communicates only with 127.0.0.1 (localhost) and all external traffic originates from a legitimate browser binary, conventional network-based detection that flags unusual outbound connections is largely bypassed. WebRTC over TURN is additionally used to conceal the attacker's true IP address from the victim's environment.
msaRAT was recovered from a compromised Windows machine ahead of ransomware encryptor deployment, indicating it is used in the pre-encryption staging phase of a Chaos intrusion. The implant enables arbitrary command execution and almost certainly serves as the primary post-compromise persistence and reconnaissance tool before the final ransomware payload is released.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs, and response recommendations — available inside the Deltabridge platform.