Overview
msaRAT is a newly identified Remote Access Trojan (RAT) used in attacks linked to the Chaos ransomware group. Unlike traditional malware that communicates directly with attacker-controlled servers, msaRAT routes its Command-and-Control (C2) traffic through legitimate Google Chrome and Microsoft Edge browser processes.
A Remote Access Trojan (RAT) is malware that allows attackers to remotely control an infected device. Command-and-Control (C2) refers to the communication channel attackers use to issue commands, steal data, or deploy additional malware on compromised systems.
By leveraging trusted browser functionality and reputable cloud services, msaRAT disguises its network activity as normal encrypted web traffic, making detection and analysis significantly more challenging for security teams.
Threat Details
The Chaos ransomware group, active since early 2025, continues to refine its tactics by abusing legitimate software and services instead of relying on easily identifiable malicious infrastructure. Attacks typically begin with email or voice phishing, where victims are tricked into installing software or granting remote access. Attackers then establish persistence using legitimate remote management tools before deploying msaRAT disguised as a Windows update.
Rather than creating its own suspicious network connections, msaRAT searches for installed versions of Google Chrome or Microsoft Edge and launches the browser in headless mode, allowing it to operate in the background without displaying a browser window to the user.
The malware then abuses the Chrome DevTools Protocol (CDP)—a legitimate interface designed for developers to debug and automate browsers—to inject JavaScript into the hidden browser session. Through this process, msaRAT establishes its Command-and-Control channel using WebRTC, a browser technology commonly used for real-time voice and video communications.
To further conceal its infrastructure, the malware leverages Cloudflare Workers to initialize communications and Twilio TURN servers to relay WebRTC traffic. These are legitimate cloud services widely used by organizations, allowing malicious communications to blend seamlessly with normal business traffic.
For additional protection, msaRAT encrypts its communications using both WebRTC's native encryption and an additional layer of ChaCha20-Poly1305 encryption with Elliptic Curve Diffie-Hellman (ECDH) key exchange. ChaCha20-Poly1305 is a modern encryption algorithm that protects transmitted data, while ECDH securely exchanges encryption keys between two systems without exposing them over the network.
Once communication is established, attackers can remotely execute Windows commands, collect system information, and maintain persistent control of the compromised endpoint while generating minimal indicators of compromise.
Recommendations
Organizations should strengthen their defenses by:
- Monitoring for unusual browser behavior, including Chrome or Edge running in headless mode or unexpected use of the Chrome DevTools Protocol.
- Investigating abnormal WebRTC connections originating from enterprise endpoints.
- Monitoring for browser processes initiated immediately after software installations or remote management activity.
- Restricting and auditing the use of remote management software to reduce opportunities for unauthorized access.
- Strengthening phishing awareness training to reduce successful initial access attempts.
- Deploying Endpoint Detection and Response (EDR) solutions capable of identifying anomalous browser behavior rather than relying solely on network-based detections.
As threat actors continue to leverage legitimate software to conceal malicious activity, organizations should prioritize behavioral detection techniques that can identify suspicious use of trusted applications, even when network traffic appears legitimate.

.jpeg)


.jpeg)


.png)

.png)
.png)