MsaRAT backdoor routes C2 through Chrome or Edge
Malware Activity
Summary
Hide ▲
Show ▼
The msaRAT backdoor now hides C2 traffic by routing it through Chrome or Microsoft Edge, making the channel harder to detect and trace. The malware is written in Rust and uses the Chrome DevTools Protocol (CDP) to control a headless browser session and inject JavaScript. It also relays communication through Cloudflare Workers and Twilio TURN, while an MSI installer posing as a Windows update loads the payload in system memory.
Related Happenings
ClickFix-based TELEPUZ distribution campaign
Campaign
H score35
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickFix-based TELEPUZ distribution campaign
CampaignAbout this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
TELEPUZ modular malware spread via ClickFix lures
Malware Activity
H score29
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The TELEPUZ malware family is actively spreading through ClickFix lures, raising the risk of credential theft and remote command execution on infected systems. The...
TELEPUZ modular malware spread via ClickFix lures
Malware ActivityAbout this happening: The TELEPUZ malware family is actively spreading through ClickFix lures, raising the risk of credential theft and remote command execution on infected systems. The...
Mistic backdoor deployment via ClickFix and DLL side-loading
Malware Activity
H score22
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...
Mistic backdoor deployment via ClickFix and DLL side-loading
Malware ActivityAbout this happening: The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
GammaWorm NTFS Alternate Data Streams propagation and backdoor activity
Malware Activity
H score40
First: 01.06.2026 14:00
Last: 01.06.2026 14:00
Sources 1
About this happening:
The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...
GammaWorm NTFS Alternate Data Streams propagation and backdoor activity
Malware ActivityAbout this happening: The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...
Timeline
-
23.07.2026 12:59 2 articles · 0h ago
Chaos ransomware gang uses msaRAT to route C2 through Chrome and Edge
Initial DisclosureCisco Talos says the Chaos ransomware gang is using msaRAT, a Rust backdoor that hides command-and-control traffic by launching Chrome or Microsoft Edge in headless mode, using the Chrome DevTools Protocol (CDP) to inject JavaScript, and relaying communication through Cloudflare Workers and Twilio TURN so the attacker’s server IP does not appear directly in network traffic. The payload is loaded by an MSI installer posing as a Windows update and runs from system memory as lib.dll.
Show sources
- New msaRAT malware uses Chrome, Edge browsers to route C2 traffic — www.bleepingcomputer.com — 23.07.2026 12:59
- New msaRAT malware uses Chrome, Edge browsers to route C2 traffic — www.bleepingcomputer.com — 23.07.2026 12:59