Home/News/New msaRAT Malware Routes C2 Traffic Via Browsers
BleepingComputer2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

New msaRAT Malware Routes C2 Traffic Via Browsers

The Chaos ransomware gang has deployed a new backdoor malware named msaRAT, which is designed to obscure its command-and-control (C2) communications by leveraging legitimate web browsers. This technique allows the malware to blend its malicious traffic with normal browsing activity, making it more difficult for security systems to detect and block.

msaRAT specifically utilizes Google Chrome and Microsoft Edge to route its C2 traffic. By embedding malicious commands and data within the normal data flow to and from these browsers, the attackers can maintain covert communication channels. This method exploits the trust and widespread use of these popular browsers, presenting a significant challenge for network defenders.

The use of browser-based C2 communication is part of a broader trend where threat actors are seeking more sophisticated methods to evade detection. Traditional security measures often focus on identifying unusual network patterns or known malicious IP addresses. However, by routing traffic through widely used applications like Chrome and Edge, msaRAT can mimic legitimate user behavior, thereby bypassing many standard security protocols. The Chaos ransomware gang's adoption of this technique highlights their evolving tactics in maintaining persistence and control over compromised systems.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next