Chaos Ransomware Uses Headless Browsers as Hidden C2 Tunnels

1 min read
Source: The Hacker News
Chaos Ransomware Uses Headless Browsers as Hidden C2 Tunnels
Photo: The Hacker News
TL;DR Summary

Cisco Talos details msaRAT, the Rust implant behind Chaos ransomware, which hijacks a compromised Windows host to drive a headless Chrome/Edge instance via the Chrome DevTools Protocol and channel all command-and-control traffic through a WebRTC data channel relayed by Twilio TURN. The malware never creates its own outbound connection; the browser handles the C2 signaling, with traffic appearing as legitimate browser activity and using a Cloudflare Worker for signaling. Delivery is via a Windows MSI that loads msaRAT in memory. No public file hashes were published as of mid-2026, but two network indicators (staging IP and a Worker hostname) are noted.

Share this article

Reading Insights

Total Reads

1

Unique Readers

8

Time Saved

4 min

vs 5 min read

Condensed

90%

992101 words

Want the full story? Read the original article

Read on The Hacker News