HackerFeeds

CyberSecurity News

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Hacker News
· July 23, 2026

AI summary

The Chaos ransomware group has been using a technique to route command-and-control traffic through a victim's own browser. This is made possible by msaRAT, a Rust-based implant discovered by Cisco Talos on a compromised Windows machine. The implant does not initiate any outbound connections on its own, instead communicating only with the local address 127.0.0.1. To facilitate communication, the implant launches either Chrome or Edge in headless mode and controls the browser. This approach allows the attackers to use the browser as a proxy for their command-and-control traffic. The implant was found ahead of the deployment of the Chaos ransomware encryptor.

Read the full article at The Hacker Newsthehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.