Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel

Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos discovered msaRAT, a new Rust-based remote access trojan used by the Chaos ransomware group, which hides its command-and-control traffic by abusing Chrome DevTools Protocol and WebRTC through a browser process. The malware uses Cloudflare Workers for signaling and Twilio TURN for relayed communications, making its network activity difficult to trace and blending it into normal browser traffic. #msaRAT #Chaos #CloudflareWorkers #TwilioTURN #ChromeDevToolsProtocol

Keypoints

  • Cisco Talos identified a new Rust-based RAT named msaRAT.
  • msaRAT is attributed to the Chaos ransomware group.
  • The malware uses Chrome DevTools Protocol to control the browser and avoid direct network access.
  • Cloudflare Workers is used for WebRTC signaling, while Twilio TURN relays the C2 connection.
  • The RAT uses double encryption and browser-based communication to conceal its activity.

Read More: https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/