Security researchers have identified a new campaign where Chaos ransomware utilizes the msaRAT tool to obfuscate command-and-control traffic. The malware routes communications through headless instances of Google Chrome and Microsoft Edge to bypass traditional network monitoring. This technique highlights the evolving sophistication of ransomware operators in evading detection. Organizations are advised to monitor for unusual browser-based traffic patterns on their endpoints. What defensive measures are most effective against browser-based C2 traffic?
Source: https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html