Home/News/Chaos Ransomware Abuses Browsers for Command and Control
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Chaos Ransomware Abuses Browsers for Command and Control

Chaos Ransomware Abuses Browsers for Command and Control

The Chaos ransomware group has been observed routing its command-and-control (C2) traffic through compromised victim browsers, specifically utilizing headless instances of Chrome and Edge. Cisco Talos detailed this technique on Thursday, identifying a Rust-based implant named msaRAT as the tool enabling this operation. This implant was discovered on a Windows machine prior to the deployment of the ransomware encryptor.

Unlike typical malware that establishes direct outbound connections to C2 servers, msaRAT operates by communicating solely with localhost (127.0.0.1). It achieves its C2 routing by initiating Chrome or Edge browsers in a headless mode, meaning the browser runs without a graphical user interface. The msaRAT implant then manipulates these headless browser processes to send and receive C2 communications, effectively masking the malicious traffic as legitimate browser activity.

This method presents a significant challenge for network defenders. By leveraging the victim's own browser infrastructure, the ransomware can bypass traditional network security controls that might otherwise detect and block suspicious outbound connections. The use of headless browsers further obscures the malicious activity, as there is no visible browser window for an end-user to notice. The discovery of msaRAT highlights an evolving tactic within the ransomware landscape, focusing on stealth and evasion by co-opting legitimate system processes.

Cisco Talos's analysis indicates that msaRAT is designed to be a versatile implant, capable of executing various commands and exfiltrating data. Its integration with headless browsers for C2 communication represents a sophisticated evasion technique. The group's reliance on this method suggests a deliberate effort to increase the survivability and effectiveness of their ransomware attacks by making their C2 infrastructure more resilient to detection and disruption.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next