Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

0
Medium
Malware
Published: 07/23/2026 (07/23/2026, 10:00:00 UTC)
Source: Bleeping Computer

Description

msaRAT is a new backdoor malware used by the Chaos ransomware gang that hides its command-and-control (C2) communication by routing traffic through headless Chrome or Edge browsers. Written in Rust, it leverages the Chrome DevTools Protocol to control the browser and establish encrypted C2 channels via Cloudflare Workers and Twilio TURN servers. This technique avoids direct network connections to the attacker’s infrastructure, making detection and attribution more difficult. The malware is delivered via a malicious MSI installer masquerading as a Windows update and runs entirely in memory. The communication uses dual-layer encryption and bypasses browser security policies to maintain stealth.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/23/2026, 10:22:25 UTC

Technical Analysis

The Chaos ransomware group employs msaRAT, a Rust-based backdoor that uses Chrome or Edge browsers in headless mode to proxy C2 communications. It controls the browser through the Chrome DevTools Protocol, injecting JavaScript to build a communication channel that bypasses Content Security Policy restrictions. msaRAT connects to a Cloudflare Workers endpoint to obtain WebRTC signaling data and establishes an encrypted WebRTC channel routed exclusively through Twilio TURN servers, preventing direct peer-to-peer connections. This design conceals the attacker’s real IP and blends C2 traffic with legitimate web traffic, complicating detection and network tracing. The malware is loaded in memory from an MSI installer disguised as a Windows update, enabling stealthy persistence and operation.

Potential Impact

The malware enables stealthy, persistent remote control of infected systems by hiding C2 traffic within legitimate browser processes and web traffic. This significantly reduces the likelihood of detection by network monitoring tools and firewalls. The use of legitimate cloud services (Cloudflare Workers and Twilio TURN) for signaling and relay further obscures attacker infrastructure. The infection vector involves social engineering and masquerading as legitimate Windows updates, increasing the risk of successful compromise. Once inside, attackers can execute commands and maintain persistence, facilitating further malicious activities such as ransomware deployment.

Mitigation Recommendations

No official patch or fix is currently available for msaRAT malware. Mitigation focuses on detection and prevention through endpoint security solutions capable of identifying suspicious use of headless browsers and unusual Chrome DevTools Protocol activity. Organizations should be vigilant against phishing and social engineering attacks that deliver malicious MSI installers. Network defenders should monitor for anomalous WebRTC traffic patterns and connections to known malicious Cloudflare Workers and Twilio TURN endpoints. Blocking or restricting the use of headless browser automation in sensitive environments may reduce risk. Refer to Cisco Talos and Rapid7 advisories for updated IoCs and detection guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/","fetched":true,"fetchedAt":"2026-07-23T10:22:16.651Z","wordCount":897}

Threat ID: 6a61eb589c2644c7f8e18ca5

Added to database: 07/23/2026, 10:22:16 UTC

Last enriched: 07/23/2026, 10:22:25 UTC

Last updated: 07/23/2026, 19:51:20 UTC

Views: 27

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses