Find notable cyber news and cases, enriched with sources, timelines, and signals.

MsaRAT backdoor routes C2 through Chrome or Edge

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The msaRAT backdoor now hides C2 traffic by routing it through Chrome or Microsoft Edge, making the channel harder to detect and trace. The malware is written in Rust and uses the Chrome DevTools Protocol (CDP) to control a headless browser session and inject JavaScript. It also relays communication through Cloudflare Workers and Twilio TURN, while an MSI installer posing as a Windows update loads the payload in system memory.

Related Happenings

ClickFix-based TELEPUZ distribution campaign

Campaign
H score35 First: 16.07.2026 15:50 Last: 16.07.2026 15:50 Sources 1

About this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...

TELEPUZ modular malware spread via ClickFix lures

Malware Activity
H score29 First: 16.07.2026 15:50 Last: 16.07.2026 15:50 Sources 1

About this happening: The TELEPUZ malware family is actively spreading through ClickFix lures, raising the risk of credential theft and remote command execution on infected systems. The...

Mistic backdoor deployment via ClickFix and DLL side-loading

Malware Activity
H score22 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...

Edgecution malicious Microsoft Edge extension backdoor activity

Malware Activity
H score23 First: 24.06.2026 23:58 Last: 24.06.2026 23:58 Sources 1

About this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...

GammaWorm NTFS Alternate Data Streams propagation and backdoor activity

Malware Activity
H score40 First: 01.06.2026 14:00 Last: 01.06.2026 14:00 Sources 1

About this happening: The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...

Timeline

  1. 23.07.2026 12:59 2 articles · 0h ago

    Chaos ransomware gang uses msaRAT to route C2 through Chrome and Edge

    Initial Disclosure

    Cisco Talos says the Chaos ransomware gang is using msaRAT, a Rust backdoor that hides command-and-control traffic by launching Chrome or Microsoft Edge in headless mode, using the Chrome DevTools Protocol (CDP) to inject JavaScript, and relaying communication through Cloudflare Workers and Twilio TURN so the attacker’s server IP does not appear directly in network traffic. The payload is loaded by an MSI installer posing as a Windows update and runs from system memory as lib.dll.

    Show sources