Chaos is hiding command-and-control inside Chrome or Edge, so perimeter tools looking for a malware beacon will miss the real channel. The RAT keeps its own traffic on localhost and pushes the external requests through a legitimate browser process, which makes the activity look like normal browser or WebRTC traffic.
Cisco Talos says the Rust-based msaRAT does this through Chrome DevTools Protocol, then uses WebRTC and relay services to carry commands and responses. The campaign is being used by Chaos ransomware after phishing or vishing access, with the browser-mediated channel lowering the value of network-only detection on any system that allows Chrome or Microsoft Edge to run WebRTC.
If your detections assume malware must open its own socket, this is the blind spot. The wider risk is not one browser or one malware family, but any intrusion that can borrow trusted browser behavior to blend command traffic into ordinary collaboration and relay services.