msaRAT malware routes command traffic through Chrome and Edge browsers
Chaos ransomware operators are hiding malicious command traffic by routing it through legitimate browser processes, complicating detection.
Browser-based command routing
The Chaos ransomware gang has deployed a new backdoor called msaRAT that conceals command-and-control communication by routing it through Chrome or Edge browser processes. This technique disguises malicious traffic as legitimate browser activity, making detection more difficult for network monitoring tools.
Traditional malware typically establishes direct connections to attacker-controlled servers. By leveraging existing browser processes, msaRAT blends into normal web traffic patterns and benefits from the browsers' encrypted connections.
Chaos ransomware infrastructure
Chaos has been active since 2021, primarily targeting small and medium-sized organizations. The group frequently updates its tooling, with msaRAT representing the latest evolution in their command-and-control infrastructure.
Security researchers have not yet disclosed specific technical details about how msaRAT manipulates browser processes or the extent of its capabilities beyond command routing. Organizations using Chrome or Edge in enterprise environments should monitor for unusual browser process behavior and network patterns.