
Chaos Ransomware Gang Deploys New msaRAT Backdoor Malware Using Chrome and Edge for C2 Traffic Evasion
ransomwaremalwarecybersecuritybackdoorbrowser_exploitationC2_evasion
The Chaos ransomware gang is deploying a new backdoor malware named msaRAT, which conceals its command-and-control (C2) traffic by routing it through Google Chrome or Microsoft Edge browsers. This technique aims to evade detection by blending malicious communications with legitimate browser traffic. No specific dates, CVE IDs, or technical indicators (e.g., hashes, IPs) were provided in the reported details. The malware’s primary function is to facilitate C2 communication, though further impacts or attack vectors were not explicitly described. The discovery highlights an evolution in threat actor tactics to bypass security monitoring.