Chaos Ransomware's msaRAT Hides C2 in Browser Traffic
The Chaos group's new msaRAT backdoor routes C2 through Chrome or Edge via WebRTC TURN relay, hiding attacker infrastructure behind the browser process.
The Chaos ransomware group is deploying a new backdoor: msaRAT. It doesn’t open a socket to a C2 server. It hijacks an installed browser — Chrome or Edge — and routes commands through WebRTC’s TURN relay infrastructure. The attacker’s IP stays behind the relay. Talos Intelligence published the analysis July 23, 2026.
Confidence
- Confirmed: msaRAT is an active Chaos group tool, per Talos.
- Confirmed: C2 traffic routes through the victim’s browser via WebRTC over TURN.
- Confirmed: Arbitrary command execution on infected hosts.
- Confirmed: Attacker IP is not exposed to the victim’s network — the relay is what egresses.
- Unconfirmed: Deployment scale and which active Chaos campaigns are carrying msaRAT.
What this changes
The egress comes from a trusted browser process, not an unknown binary opening a raw socket. Network controls that block unfamiliar outbound connections or unknown IPs don’t see it. The relevant detection surface shifts to endpoint: browser process ancestry, unexpected WebRTC initiations from non-user-driven contexts, process injection signals.
Living-off-the-browser, alongside living-off-the-land, is now operational in a ransomware-as-a-service context. That’s the signal here.
What to watch
Talos’ write-up has indicators and detection guidance. BleepingComputer carries additional campaign context. Chaos has iterated tooling fast in the past — initial deployment scope is likely to expand.
For related ransomware campaign coverage: Stadler Rail refuses $12.3M Everest ransom.
Found this useful? Share it.


