Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both browsers. The...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3660639
🛡️ Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
⏱️ vor 9d 17h (23.07.2026 um 12:38 Uhr) 📂 📰 IT Security Nachrichten 📡 Feed 🔗 Quelle: helpnetsecurity.com