Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chaos Ransomware Uses Headless Browsers for Stealthy Attacks

Chaos Ransomware Uses Headless Browsers for Stealthy Attacks

Posted on July 23, 2026 By CWS

The Chaos ransomware group has devised a novel method to manage command-and-control (C2) traffic using the victim’s own web browser. Cisco Talos recently uncovered the Rust-based msaRAT implant, which was detected on a compromised Windows system prior to encryption activities.

Innovative Command-and-Control Method

The msaRAT implant operates without initiating any outbound connections itself. Instead, it communicates with the local host address 127.0.0.1, employing Chrome or Edge in a headless mode through the Chrome DevTools Protocol (CDP). This technique facilitates the transmission of C2 messages via a WebRTC data channel, relayed by Twilio’s TURN service. Consequently, network defenders observe browser traffic directed to Cloudflare and Twilio, obscuring the attacker’s server address.

Technical Details of msaRAT Operations

msaRAT first searches for Chrome or Edge through environment variables and then checks the registry if necessary. Upon finding a compatible browser, it initiates it in headless mode, utilizing specific flags to enable remote debugging and point to a distinct user data directory. Google’s Chrome 136 update, which prevents debugging against the default profile, does not hinder msaRAT as it uses its own profile directory.

The implant requests a debuggable target and connects to the returned WebSocket URL, creating a new tab and disabling Content Security Policy. It registers multiple callbacks and injects JavaScript to facilitate communication. This script retrieves STUN and TURN configurations from a Cloudflare Worker, masked as Microsoft site traffic, establishing a peer connection through Twilio’s relay.

Security Implications and Defensive Measures

msaRAT’s deployment follows initial system compromise, taking place before encryption begins. Although Cisco Talos has not disclosed the specific attack vector, common tactics include spam, vishing, Quick Assist, and remote management tools. The implant is delivered via a simple curl command, masquerading as a legitimate Windows update.

Defense against msaRAT involves monitoring browser behaviors, particularly non-interactive launches of Chrome or Edge in headless mode. Correlating such processes with loopback traffic and outbound WebRTC communications is crucial. Although no file hashes for msaRAT are publicly available, Talos provides network indicators such as a staging IP and a Worker hostname.

This report highlights the strategic use of headless browsers in cyberattacks. While the specific victim and the extent of msaRAT’s deployment remain undisclosed, the reliance on legitimate services like Cloudflare and Twilio emphasizes the need for vigilant network monitoring and robust cybersecurity practices.

The Hacker News Tags:Chaos ransomware, Chrome DevTools Protocol, Cisco Talos, Cloudflare, Cybersecurity, headless browsers, msaRAT, Rust malware, Twilio, WebRTC

Post navigation

Previous Post: Ubuntu Snap-confine Vulnerability Risks Root Access
Next Post: AI Revolutionizes Vulnerability Management in Cybersecurity

Related Posts

MuddyWater Exploits Teams for Credential Theft in Covert Attack MuddyWater Exploits Teams for Credential Theft in Covert Attack The Hacker News
Russian Cyber Campaign Targets Ukraine with New Malware Russian Cyber Campaign Targets Ukraine with New Malware The Hacker News
INTERPOL’s Cybercrime Crackdown Nets 651 Arrests in Africa INTERPOL’s Cybercrime Crackdown Nets 651 Arrests in Africa The Hacker News
Five New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Among Targets Five New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Among Targets The Hacker News
Microsoft Addresses Critical SharePoint Security Flaw Microsoft Addresses Critical SharePoint Security Flaw The Hacker News
DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Global Espionage Unveiled by Hackers’ Security Error
  • AI Revolutionizes Vulnerability Management in Cybersecurity
  • Chaos Ransomware Uses Headless Browsers for Stealthy Attacks
  • Ubuntu Snap-confine Vulnerability Risks Root Access
  • OpenAI Resolves Security Flaw in ChatGPT Agents

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Global Espionage Unveiled by Hackers’ Security Error
  • AI Revolutionizes Vulnerability Management in Cybersecurity
  • Chaos Ransomware Uses Headless Browsers for Stealthy Attacks
  • Ubuntu Snap-confine Vulnerability Risks Root Access
  • OpenAI Resolves Security Flaw in ChatGPT Agents

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark