Skip to main content
CyberSingle-sourceMediumDeveloping
5.5

Chaos ransomware utilizes WebRTC via headless browsers for C2 obfuscation

The Chaos ransomware variant msaRAT has adopted a new evasion technique by launching headless Chrome or Edge instances to tunnel command-and-control traffic through WebRTC. This method masks malicious communications as legitimate browser-based traffic, complicating network-level detection and traffic analysis.

The Hacker News1 day agoCredibility 54%View source

Score Breakdown

Mosaic Score5.5
Confidence0.9
Significance0.5
Source credibility0.5
Source

Related signals

8 found