New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
msaRAT is a new backdoor malware used by the Chaos ransomware gang that hides its command-and-control (C2) communication by routing traffic through headless Chrome or Edge browsers. Written in Rust, it leverages the Chrome DevTools Protocol to control the browser and establish encrypted C2 channels via Cloudflare Workers and Twilio TURN servers. This technique avoids direct network connections to the attacker’s infrastructure, making detection and attribution more difficult. The malware is delivered via a malicious MSI installer masquerading as a Windows update and runs entirely in memory. The communication uses dual-layer encryption and bypasses browser security policies to maintain stealth.
AI Analysis
Technical Summary
The Chaos ransomware group employs msaRAT, a Rust-based backdoor that uses Chrome or Edge browsers in headless mode to proxy C2 communications. It controls the browser through the Chrome DevTools Protocol, injecting JavaScript to build a communication channel that bypasses Content Security Policy restrictions. msaRAT connects to a Cloudflare Workers endpoint to obtain WebRTC signaling data and establishes an encrypted WebRTC channel routed exclusively through Twilio TURN servers, preventing direct peer-to-peer connections. This design conceals the attacker’s real IP and blends C2 traffic with legitimate web traffic, complicating detection and network tracing. The malware is loaded in memory from an MSI installer disguised as a Windows update, enabling stealthy persistence and operation.
Potential Impact
The malware enables stealthy, persistent remote control of infected systems by hiding C2 traffic within legitimate browser processes and web traffic. This significantly reduces the likelihood of detection by network monitoring tools and firewalls. The use of legitimate cloud services (Cloudflare Workers and Twilio TURN) for signaling and relay further obscures attacker infrastructure. The infection vector involves social engineering and masquerading as legitimate Windows updates, increasing the risk of successful compromise. Once inside, attackers can execute commands and maintain persistence, facilitating further malicious activities such as ransomware deployment.
Mitigation Recommendations
No official patch or fix is currently available for msaRAT malware. Mitigation focuses on detection and prevention through endpoint security solutions capable of identifying suspicious use of headless browsers and unusual Chrome DevTools Protocol activity. Organizations should be vigilant against phishing and social engineering attacks that deliver malicious MSI installers. Network defenders should monitor for anomalous WebRTC traffic patterns and connections to known malicious Cloudflare Workers and Twilio TURN endpoints. Blocking or restricting the use of headless browser automation in sensitive environments may reduce risk. Refer to Cisco Talos and Rapid7 advisories for updated IoCs and detection guidance.
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Description
msaRAT is a new backdoor malware used by the Chaos ransomware gang that hides its command-and-control (C2) communication by routing traffic through headless Chrome or Edge browsers. Written in Rust, it leverages the Chrome DevTools Protocol to control the browser and establish encrypted C2 channels via Cloudflare Workers and Twilio TURN servers. This technique avoids direct network connections to the attacker’s infrastructure, making detection and attribution more difficult. The malware is delivered via a malicious MSI installer masquerading as a Windows update and runs entirely in memory. The communication uses dual-layer encryption and bypasses browser security policies to maintain stealth.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Chaos ransomware group employs msaRAT, a Rust-based backdoor that uses Chrome or Edge browsers in headless mode to proxy C2 communications. It controls the browser through the Chrome DevTools Protocol, injecting JavaScript to build a communication channel that bypasses Content Security Policy restrictions. msaRAT connects to a Cloudflare Workers endpoint to obtain WebRTC signaling data and establishes an encrypted WebRTC channel routed exclusively through Twilio TURN servers, preventing direct peer-to-peer connections. This design conceals the attacker’s real IP and blends C2 traffic with legitimate web traffic, complicating detection and network tracing. The malware is loaded in memory from an MSI installer disguised as a Windows update, enabling stealthy persistence and operation.
Potential Impact
The malware enables stealthy, persistent remote control of infected systems by hiding C2 traffic within legitimate browser processes and web traffic. This significantly reduces the likelihood of detection by network monitoring tools and firewalls. The use of legitimate cloud services (Cloudflare Workers and Twilio TURN) for signaling and relay further obscures attacker infrastructure. The infection vector involves social engineering and masquerading as legitimate Windows updates, increasing the risk of successful compromise. Once inside, attackers can execute commands and maintain persistence, facilitating further malicious activities such as ransomware deployment.
Mitigation Recommendations
No official patch or fix is currently available for msaRAT malware. Mitigation focuses on detection and prevention through endpoint security solutions capable of identifying suspicious use of headless browsers and unusual Chrome DevTools Protocol activity. Organizations should be vigilant against phishing and social engineering attacks that deliver malicious MSI installers. Network defenders should monitor for anomalous WebRTC traffic patterns and connections to known malicious Cloudflare Workers and Twilio TURN endpoints. Blocking or restricting the use of headless browser automation in sensitive environments may reduce risk. Refer to Cisco Talos and Rapid7 advisories for updated IoCs and detection guidance.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/","fetched":true,"fetchedAt":"2026-07-23T10:22:16.651Z","wordCount":897}
Threat ID: 6a61eb589c2644c7f8e18ca5
Added to database: 07/23/2026, 10:22:16 UTC
Last enriched: 07/23/2026, 10:22:25 UTC
Last updated: 07/23/2026, 19:51:20 UTC
Views: 27
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.