THREATOPS
THREAT OPSThreat News › Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

medtalosPublished 2026-07-23

<ul><li>Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call &#x201c;msaRAT&#x201d; attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: &#x201c;msaOpen,&#x201d; &#x201c;msaClose,&#x201d; &#x201c;msaError,&#x201d; and &#x201c;msaMessage&#x201d;.</li><li>msaRAT is implemented using the Tokio asynchronous runtime, with pr

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/