Tag

Chaos Ransomware

All articles tagged with #chaos ransomware

Teams Impersonations Fuel Chaos Ransomware Deployments Across North America
security1 month ago

Teams Impersonations Fuel Chaos Ransomware Deployments Across North America

Sophos warns of STAC4749, a vishing campaign in which external Microsoft Teams calls impersonate IT staff to gain remote access, deploying backdoors and culminating in Chaos ransomware across dozens of North American organizations (Canada ~50%, US ~45%). Attackers used fake IT domains under the .top TLD, relied on Quick Assist or RemSupp, then PowerShell to install persistence and remote access tools like DWAgent/AnyDesk, with RDP used for lateral movement. Ransomware encrypts files and may accompany data theft; Chaos-as-a-service is linked to Conti offshoots. The techniques evolved to evade detection; no confirmed link to MuddyWater.

Chaos Ransomware Uses Headless Browsers as Hidden C2 Tunnels
cybersecurity1 month ago

Chaos Ransomware Uses Headless Browsers as Hidden C2 Tunnels

Cisco Talos details msaRAT, the Rust implant behind Chaos ransomware, which hijacks a compromised Windows host to drive a headless Chrome/Edge instance via the Chrome DevTools Protocol and channel all command-and-control traffic through a WebRTC data channel relayed by Twilio TURN. The malware never creates its own outbound connection; the browser handles the C2 signaling, with traffic appearing as legitimate browser activity and using a Cloudflare Worker for signaling. Delivery is via a Windows MSI that loads msaRAT in memory. No public file hashes were published as of mid-2026, but two network indicators (staging IP and a Worker hostname) are noted.