msaRAT malware routes command traffic through Chrome and Edge browsers

Chaos ransomware operators are hiding malicious command traffic by routing it through legitimate browser processes, complicating detection.

Abstract illustration of concealed network traffic routing
AI-generated illustration · Sylvaris

Browser-based command routing

The Chaos ransomware gang has deployed a new backdoor called msaRAT that conceals command-and-control communication by routing it through Chrome or Edge browser processes. This technique disguises malicious traffic as legitimate browser activity, making detection more difficult for network monitoring tools.

Traditional malware typically establishes direct connections to attacker-controlled servers. By leveraging existing browser processes, msaRAT blends into normal web traffic patterns and benefits from the browsers' encrypted connections.

Chaos ransomware infrastructure

Chaos has been active since 2021, primarily targeting small and medium-sized organizations. The group frequently updates its tooling, with msaRAT representing the latest evolution in their command-and-control infrastructure.

Security researchers have not yet disclosed specific technical details about how msaRAT manipulates browser processes or the extent of its capabilities beyond command routing. Organizations using Chrome or Edge in enterprise environments should monitor for unusual browser process behavior and network patterns.

sources
more in Security
Google adds selfie video verification for account recovery Google's new biometric recovery option provides account access when traditional two-factor authentication methods are unavailable. Check Point SmartConsole zero-day under active exploitation Active exploitation of administrative interface zero-days enables attackers to compromise enterprise network security infrastructure at scale. Social engineering attack bypasses physical security, grants unauthorized access to medical records Physical security controls remain vulnerable to social engineering tactics that exploit human trust rather than technical systems.