Chaos Ransomware Uses Headless Browsers as Hidden C2 Tunnels

TL;DR Summary
Cisco Talos details msaRAT, the Rust implant behind Chaos ransomware, which hijacks a compromised Windows host to drive a headless Chrome/Edge instance via the Chrome DevTools Protocol and channel all command-and-control traffic through a WebRTC data channel relayed by Twilio TURN. The malware never creates its own outbound connection; the browser handles the C2 signaling, with traffic appearing as legitimate browser activity and using a Cloudflare Worker for signaling. Delivery is via a Windows MSI that loads msaRAT in memory. No public file hashes were published as of mid-2026, but two network indicators (staging IP and a Worker hostname) are noted.
Topics:technology#c2-tunneling#chaos-ransomware#chrome-devtools-protocol#cybersecurity#msarat#webrtc
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Hacker News
- Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Cisco Talos Blog
- Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel CyberSecurityNews
- Chaos ransomware deploys browser-based msaRAT to evade network detection Security Affairs
- Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process Help Net Security
Reading Insights
Total Reads
1
Unique Readers
8
Time Saved
4 min
vs 5 min read
Condensed
90%
992 → 101 words
Want the full story? Read the original article
Read on The Hacker News