Security · 4h ago
Chaos Ransomware Hijacks Chrome and Edge for Stealthy C2
The Chaos ransomware group uses a Rust-based implant called msaRAT to route command-and-control traffic through the victim's own Chrome or Edge browser in headless mode. Cisco Talos discovered the implant on a compromised Windows machine, where it communicates only with localhost, avoiding outbound connections. This technique makes detection harder by blending malicious traffic with legitimate browser activity.
Meridian48 take
The approach is clever but not unprecedented; similar browser-based C2 methods have been seen before, though this Rust implementation adds a modern twist.
Read the full reporting
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge →
The Hacker News
chaos-ransomwaremsarat