New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

Summary

A new backdoor malware named msaRAT, allegedly developed by the Chaos ransomware gang, is using legitimate Chrome and Edge browser processes to conceal its command-and-control (C2) traffic. This technique makes it difficult to detect and block the malware's communication by blending malicious traffic with normal browser activity.

IFF Assessment

FOE

The development and use of new malware that evades detection by leveraging common applications like web browsers represent a significant challenge and threat to defenders.

Defender Context

Defenders should be aware of techniques that abuse legitimate browser processes for C2 communication. Monitoring network traffic for unusual patterns related to browser activity and implementing endpoint detection and response (EDR) solutions capable of deep process inspection are crucial steps.

Read Full Story →