CyberNotableSingle-sourceDeveloping
5.5
Chaos ransomware group deploys msaRAT backdoor using browser-based C2 obfuscation
BleepingComputer·1 day ago
The Chaos ransomware variant msaRAT has adopted a new evasion technique by launching headless Chrome or Edge instances to tunnel command-and-control traffic through WebRTC. This method masks malicious communications as legitimate browser-based traffic, complicating network-level detection and traffic analysis.