Security News

Cybersecurity news aggregator

⚔️
HIGH Attacks Help Net Security

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

The Chaos ransomware group is using a new Rust-based RAT, msaRAT, which establishes its command-and-control channel by launching a legitimate Chrome or Edge browser instance and controlling it via the Chrome DevTools Protocol, thereby hiding malicious WebRTC traffic within a trusted browser process.
Read Full Article →

Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both browsers. The browser then carries the command-and-control traffic over a WebRTC channel. Once installed, the RAT process keeps all of … More → The post Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process appeared first on Help Net Security .

Share this article