New msaRAT Malware Hides Communications Inside Chrome and Edge.

23.07.2026

New msaRAT Malware Hides Communications Inside Chrome and Edge. Cisco Talos researchers have documented a Rust-based backdoor called msaRAT, currently associated with attacks by the Chaos ransomware group. The malware launches Chrome or Microsoft Edge in headless mode and uses…

Източник: www.bleepingcomputer.com

New msaRAT Malware Hides Communications Inside Chrome and Edge.

Cisco Talos researchers have documented a Rust-based backdoor called msaRAT, currently associated with attacks by the Chaos ransomware group. The malware launches Chrome or Microsoft Edge in headless mode and uses the Chrome DevTools Protocol to inject JavaScript and create its command-and-control channel. Because the traffic originates from a legitimate browser process, the malware does not connect directly to the attacker’s infrastructure, making conventional network detection more difficult. It uses WebRTC, Cloudflare Workers and Twilio relay servers, while communications are protected by two encryption layers. Observed infections began with phishing and a malicious MSI installer disguised as a Windows update.