Cisco Talos Exposes Rust-Based RAT That Hides C2 Traffic Inside Chrome Browser
Cisco Talos published analysis on July 23 of a Rust-based remote access trojan called msaRAT, attributed to the Chaos ransomware group. The malware never opens a direct outbound network connection; instead, it launches Chrome or Edge in headless mode and routes all command-and-control traffic through the browser process via Chrome DevTools Protocol, making it appear to firewalls and endpoint tools as if the RAT only communicates with localhost. Separately, Sophos documented a related campaign, tracked as STAC4749, in which attackers impersonated IT helpdesk staff over Microsoft Teams calls to trick targets into granting remote access, ultimately deploying Chaos ransomware in at least three confirmed cases. The campaign used deceptive persistence techniques such as Run registry keys and startup shortcuts named to mimic legitimate system components like Realtek audio drivers and OneDriveUpdate. Golang implants used embedded CA certificates with custom issuer names to enforce certificate pinning, effectively segmenting their infrastructure so each payload only connected to its designated C2 server.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in