← Back to Feed

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

July 23, 2026 · Talos Intelligence · Severity: CRITICAL

Has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group.

Key Takeaways

  • has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group.
  • The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and &#x20.
  • This RAT never touches the network directly — it controls its C2 communication channel exclusively through Chrome DevTools Protocol (CDP), a br.
☕ Buy a Coffee