msaRAT backdoor tunnels C2 through Chrome and Edge to evade detection
Source headline: New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Intelligence Summary
Chaos ransomware operators have introduced a new backdoor called msaRAT. The malware hides command-and-control communications by routing traffic through the Chrome and Microsoft Edge browsers. This approach can make malicious activity blend in with normal browser behavior. By using legitimate browser components as a proxy, msaRAT may complicate network monitoring and detection. Organizations should review endpoint activity involving browser-driven network traffic and watch for related persistence or backdoor indicators.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.