Threats & Adversaries · Ransomware
Browser Traffic Becomes the Command Channel Chaos is hiding command-and-control inside Chrome or Edge, so perimeter tools looking for a malware beacon will miss the real channel. The RAT keeps its own traffic on localhost and pushes the external requests through a legitimate browser process, which makes the activity look like normal browser or WebRTC traffic.
Cisco Talos says the Rust-based msaRAT does this through Chrome DevTools Protocol, then uses WebRTC and relay services to carry commands and responses. The campaign is being used by Chaos ransomware after phishing or vishing access, with the browser-mediated channel lowering the value of network-only detection on any system that allows Chrome or Microsoft Edge to run WebRTC.
If your detections assume malware must open its own socket, this is the blind spot. The wider risk is not one browser or one malware family, but any intrusion that can borrow trusted browser behavior to blend command traffic into ordinary collaboration and relay services.
4 sources · Jul 23
Timeline Sources Jul 23 The Hacker News
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Chaos-linked msaRAT drives headless Chrome or Edge over CDP, relaying encrypted C2 through Twilio TURN while its own process stays on loopback.
original Jul 23 Help Net Security
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process - Help Net Security
Chaos ransomware's new msaRAT hijacks headless Chrome to run its C2, so attacker traffic leaves the host as ordinary WebRTC, researchers say.
original Jul 23 Talos Intelligence
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-07-23
Every edition of this story: Browser Traffic Becomes the Command Channel
More from today
Threats & Adversaries · Ransomware
Browser Traffic Becomes the Command Channel Chaos is hiding command-and-control inside Chrome or Edge, so perimeter tools looking for a malware beacon will miss the real channel. The RAT keeps its own traffic on localhost and pushes the external requests through a legitimate browser process, which makes the activity look like normal browser or WebRTC traffic.
Cisco Talos says the Rust-based msaRAT does this through Chrome DevTools Protocol, then uses WebRTC and relay services to carry commands and responses. The campaign is being used by Chaos ransomware after phishing or vishing access, with the browser-mediated channel lowering the value of network-only detection on any system that allows Chrome or Microsoft Edge to run WebRTC.
If your detections assume malware must open its own socket, this is the blind spot. The wider risk is not one browser or one malware family, but any intrusion that can borrow trusted browser behavior to blend command traffic into ordinary collaboration and relay services.
4 sources · Jul 23
Timeline Sources Jul 23 The Hacker News
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Chaos-linked msaRAT drives headless Chrome or Edge over CDP, relaying encrypted C2 through Twilio TURN while its own process stays on loopback.
original Jul 23 Help Net Security
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process - Help Net Security
Chaos ransomware's new msaRAT hijacks headless Chrome to run its C2, so attacker traffic leaves the host as ordinary WebRTC, researchers say.
original Jul 23 Talos Intelligence
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-07-23
Every edition of this story: Browser Traffic Becomes the Command Channel
More from today