THREAT OPS › Threat News › Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
<ul><li>Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”.</li><li>msaRAT is implemented using the Tokio asynchronous runtime, with pr
MITRE ATT&CK techniques
Indicators of compromise
- http://172.86.126.18:443/update_ms.msiurl
- https://tokio.rs/url
- 172.86.126.18ipv4
- storage.ghost.iodomain
- global.turn.twilio.comdomain