Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chaos Ransomware Uses Headless Browsers for Stealthy Attacks

Chaos Ransomware Uses Headless Browsers for Stealthy Attacks

Posted on July 23, 2026 By CWS

The Chaos ransomware group has devised a novel method to manage command-and-control (C2) traffic using the victim’s own web browser. Cisco Talos recently uncovered the Rust-based msaRAT implant, which was detected on a compromised Windows system prior to encryption activities.

Innovative Command-and-Control Method

The msaRAT implant operates without initiating any outbound connections itself. Instead, it communicates with the local host address 127.0.0.1, employing Chrome or Edge in a headless mode through the Chrome DevTools Protocol (CDP). This technique facilitates the transmission of C2 messages via a WebRTC data channel, relayed by Twilio’s TURN service. Consequently, network defenders observe browser traffic directed to Cloudflare and Twilio, obscuring the attacker’s server address.

Technical Details of msaRAT Operations

msaRAT first searches for Chrome or Edge through environment variables and then checks the registry if necessary. Upon finding a compatible browser, it initiates it in headless mode, utilizing specific flags to enable remote debugging and point to a distinct user data directory. Google’s Chrome 136 update, which prevents debugging against the default profile, does not hinder msaRAT as it uses its own profile directory.

The implant requests a debuggable target and connects to the returned WebSocket URL, creating a new tab and disabling Content Security Policy. It registers multiple callbacks and injects JavaScript to facilitate communication. This script retrieves STUN and TURN configurations from a Cloudflare Worker, masked as Microsoft site traffic, establishing a peer connection through Twilio’s relay.

Security Implications and Defensive Measures

msaRAT’s deployment follows initial system compromise, taking place before encryption begins. Although Cisco Talos has not disclosed the specific attack vector, common tactics include spam, vishing, Quick Assist, and remote management tools. The implant is delivered via a simple curl command, masquerading as a legitimate Windows update.

Defense against msaRAT involves monitoring browser behaviors, particularly non-interactive launches of Chrome or Edge in headless mode. Correlating such processes with loopback traffic and outbound WebRTC communications is crucial. Although no file hashes for msaRAT are publicly available, Talos provides network indicators such as a staging IP and a Worker hostname.

This report highlights the strategic use of headless browsers in cyberattacks. While the specific victim and the extent of msaRAT’s deployment remain undisclosed, the reliance on legitimate services like Cloudflare and Twilio emphasizes the need for vigilant network monitoring and robust cybersecurity practices.

The Hacker News Tags:Chaos ransomware, Chrome DevTools Protocol, Cisco Talos, Cloudflare, Cybersecurity, headless browsers, msaRAT, Rust malware, Twilio, WebRTC

Post navigation

Previous Post: Ubuntu Snap-confine Vulnerability Risks Root Access
Next Post: AI Revolutionizes Vulnerability Management in Cybersecurity

Related Posts

Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches The Hacker News
CrashStealer Malware Bypasses macOS Gatekeeper CrashStealer Malware Bypasses macOS Gatekeeper The Hacker News
Google Fined 9 Million by French Regulator for Cookie Consent Violations Google Fined $379 Million by French Regulator for Cookie Consent Violations The Hacker News
From Browser Stealer to Intelligence-Gathering Tool From Browser Stealer to Intelligence-Gathering Tool The Hacker News
GitHub Probes Alleged Security Breach by TeamPCP GitHub Probes Alleged Security Breach by TeamPCP The Hacker News
Microsoft Addresses Critical SharePoint Security Flaw Microsoft Addresses Critical SharePoint Security Flaw The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks
  • Next.js Addresses Critical Security Vulnerabilities
  • Chick-fil-A Data Breach Exposes Customer Information
  • Emerging Cyber Threats: Android Spyware and AI Attacks
  • Global Espionage Unveiled by Hackers’ Security Error

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks
  • Next.js Addresses Critical Security Vulnerabilities
  • Chick-fil-A Data Breach Exposes Customer Information
  • Emerging Cyber Threats: Android Spyware and AI Attacks
  • Global Espionage Unveiled by Hackers’ Security Error

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark