Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chaos Ransomware Uses Headless Browsers for Stealthy Attacks

Chaos Ransomware Uses Headless Browsers for Stealthy Attacks

Posted on July 23, 2026 By CWS

The Chaos ransomware group has devised a novel method to manage command-and-control (C2) traffic using the victim’s own web browser. Cisco Talos recently uncovered the Rust-based msaRAT implant, which was detected on a compromised Windows system prior to encryption activities.

Innovative Command-and-Control Method

The msaRAT implant operates without initiating any outbound connections itself. Instead, it communicates with the local host address 127.0.0.1, employing Chrome or Edge in a headless mode through the Chrome DevTools Protocol (CDP). This technique facilitates the transmission of C2 messages via a WebRTC data channel, relayed by Twilio’s TURN service. Consequently, network defenders observe browser traffic directed to Cloudflare and Twilio, obscuring the attacker’s server address.

Technical Details of msaRAT Operations

msaRAT first searches for Chrome or Edge through environment variables and then checks the registry if necessary. Upon finding a compatible browser, it initiates it in headless mode, utilizing specific flags to enable remote debugging and point to a distinct user data directory. Google’s Chrome 136 update, which prevents debugging against the default profile, does not hinder msaRAT as it uses its own profile directory.

The implant requests a debuggable target and connects to the returned WebSocket URL, creating a new tab and disabling Content Security Policy. It registers multiple callbacks and injects JavaScript to facilitate communication. This script retrieves STUN and TURN configurations from a Cloudflare Worker, masked as Microsoft site traffic, establishing a peer connection through Twilio’s relay.

Security Implications and Defensive Measures

msaRAT’s deployment follows initial system compromise, taking place before encryption begins. Although Cisco Talos has not disclosed the specific attack vector, common tactics include spam, vishing, Quick Assist, and remote management tools. The implant is delivered via a simple curl command, masquerading as a legitimate Windows update.

Defense against msaRAT involves monitoring browser behaviors, particularly non-interactive launches of Chrome or Edge in headless mode. Correlating such processes with loopback traffic and outbound WebRTC communications is crucial. Although no file hashes for msaRAT are publicly available, Talos provides network indicators such as a staging IP and a Worker hostname.

This report highlights the strategic use of headless browsers in cyberattacks. While the specific victim and the extent of msaRAT’s deployment remain undisclosed, the reliance on legitimate services like Cloudflare and Twilio emphasizes the need for vigilant network monitoring and robust cybersecurity practices.

The Hacker News Tags:Chaos ransomware, Chrome DevTools Protocol, Cisco Talos, Cloudflare, Cybersecurity, headless browsers, msaRAT, Rust malware, Twilio, WebRTC

Post navigation

Previous Post: Ubuntu Snap-confine Vulnerability Risks Root Access
Next Post: AI Revolutionizes Vulnerability Management in Cybersecurity

Related Posts

New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks The Hacker News
CISOs Tackle Burnout and Reduce MTTR Without Extra Staff CISOs Tackle Burnout and Reduce MTTR Without Extra Staff The Hacker News
CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely The Hacker News
North Korean Hackers Use Fake Microsoft Alerts to Spread NarwhalRAT North Korean Hackers Use Fake Microsoft Alerts to Spread NarwhalRAT The Hacker News
New Flaws and AI Threats Shape Cybersecurity Landscape New Flaws and AI Threats Shape Cybersecurity Landscape The Hacker News
Critical Mitel Flaw Lets Hackers Bypass Login, Gain Full Access to MiVoice MX-ONE Systems Critical Mitel Flaw Lets Hackers Bypass Login, Gain Full Access to MiVoice MX-ONE Systems The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark