ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

msaRAT backdoor tunnels C2 through Chrome and Edge to evade detection

Source headline: New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

Chaos ransomware operators have introduced a new backdoor called msaRAT. The malware hides command-and-control communications by routing traffic through the Chrome and Microsoft Edge browsers. This approach can make malicious activity blend in with normal browser behavior. By using legitimate browser components as a proxy, msaRAT may complicate network monitoring and detection. Organizations should review endpoint activity involving browser-driven network traffic and watch for related persistence or backdoor indicators.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#chrome #backdoor #c2 #edge #browser-proxy #chaos-ransomware #msarat
Original reporting BleepingComputer New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Open original source