threat-intel Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers Researchers have discovered a post-exploitation technique leveraging Chrome DevTools Protocol (CDP) to steal cookies and sensitive data from running instances of Chrome and Edge on Windows. This method bypasses standard browser protections, such as Device Bound Session Credentials, and allows attackers to gain full con… The Hacker News · Aug 14, 2026 High cdpdevtoolscookie theft
threat-intel Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group is utilizing a sophisticated technique involving msaRAT, a Rust-based implant, to establish a command-and-control channel. msaRAT leverages a headless Chrome or Edge browser, communicating thro… The Hacker News · Jul 23, 2026 High ransomwarec2webrtc
threat-intel Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel The Chaos ransomware group is utilizing a new Rust-based remote access Trojan (RAT) called ‘msaRAT’ to infiltrate networks. MsaRAT leverages browser debugging protocols (CDP), specifically Chrome DevTools Protocol, to es… Cisco Talos · Jul 23, 2026 High ransomwarebrowserwebrtc