threat-intel Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group is utilizing a sophisticated technique involving msaRAT, a Rust-based implant, to establish a command-and-control channel. msaRAT leverages a headless Chrome or Edge browser, communicating through the browser's debugging API (CDP) and a WebRTC data channel relayed by Twilio's TURN service, ef… The Hacker News · Jul 23, 2026 High ransomwarec2webrtc
threat-intel Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel The Chaos ransomware group is utilizing a new Rust-based remote access Trojan (RAT) called ‘msaRAT’ to infiltrate networks. MsaRAT leverages browser debugging protocols (CDP), specifically Chrome DevTools Protocol, to es… Cisco Talos · Jul 23, 2026 High ransomwarebrowserwebrtc
malware Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Two separate malware campaigns are targeting Windows and Android users across Latin America and Europe, primarily focusing on banking trojans. The first campaign utilizes the Grandoreiro malware, an actively evolving ban… The Hacker News · May 27, 2026 High PTBRESbanking trojanandroid malwaredll side-loading