MsaRAT backdoor routes C2 through Chrome or Edge
Malware Activity
Summary
Hide ▲
Show ▼
Chaos ransomware is using msaRAT, a Rust backdoor, to route C2 through headless Chrome or Microsoft Edge on a compromised Windows host. Cisco Talos says the implant uses CDP to drive the browser, then relays traffic through Cloudflare Workers and Twilio TURN so the attacker’s server IP does not appear directly on the wire. The delivery chain starts with curl.exe fetching a fake Windows update MSI from 172.86.126[.]18:443, which loads lib.dll in memory before the encryptor runs.
Related Happenings
ClickFix-based TELEPUZ distribution campaign
Campaign
H score35
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickFix-based TELEPUZ distribution campaign
CampaignAbout this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
TELEPUZ modular malware spread via ClickFix lures
Malware Activity
H score29
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The TELEPUZ malware family is actively spreading through ClickFix lures, raising the risk of credential theft and remote command execution on infected systems. The...
TELEPUZ modular malware spread via ClickFix lures
Malware ActivityAbout this happening: The TELEPUZ malware family is actively spreading through ClickFix lures, raising the risk of credential theft and remote command execution on infected systems. The...
Mistic backdoor deployment via ClickFix and DLL side-loading
Malware Activity
H score22
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...
Mistic backdoor deployment via ClickFix and DLL side-loading
Malware ActivityAbout this happening: The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
GammaWorm NTFS Alternate Data Streams propagation and backdoor activity
Malware Activity
H score40
First: 01.06.2026 14:00
Last: 01.06.2026 14:00
Sources 1
About this happening:
The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...
GammaWorm NTFS Alternate Data Streams propagation and backdoor activity
Malware ActivityAbout this happening: The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...
Timeline
-
23.07.2026 12:59 3 articles · 13d ago
Chaos ransomware gang uses msaRAT to route C2 through Chrome and Edge
Initial DisclosureCisco Talos says the Chaos ransomware gang is using msaRAT, a Rust backdoor that hides command-and-control traffic by launching Chrome or Microsoft Edge in headless mode, using the Chrome DevTools Protocol (CDP) to inject JavaScript, and relaying communication through Cloudflare Workers and Twilio TURN so the attacker’s server IP does not appear directly in network traffic. The payload is loaded by an MSI installer posing as a Windows update and runs from system memory as lib.dll.
Show sources
- New msaRAT malware uses Chrome, Edge browsers to route C2 traffic — www.bleepingcomputer.com — 23.07.2026 12:59
- New msaRAT malware uses Chrome, Edge browsers to route C2 traffic — www.bleepingcomputer.com — 23.07.2026 12:59
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge — thehackernews.com — 23.07.2026 16:11