Cisco Talos discovered msaRAT, a new Rust-based remote access trojan used by the Chaos ransomware group, which hides its command-and-control traffic by abusing Chrome DevTools Protocol and WebRTC through a browser process. The malware uses Cloudflare Workers for signaling and Twilio TURN for relayed communications, making its network activity difficult to trace and blending it into normal browser traffic. #msaRAT #Chaos #CloudflareWorkers #TwilioTURN #ChromeDevToolsProtocol
Keypoints
- Cisco Talos identified a new Rust-based RAT named msaRAT.
- msaRAT is attributed to the Chaos ransomware group.
- The malware uses Chrome DevTools Protocol to control the browser and avoid direct network access.
- Cloudflare Workers is used for WebRTC signaling, while Twilio TURN relays the C2 connection.
- The RAT uses double encryption and browser-based communication to conceal its activity.
Read More: https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/