CVE Tools

Don’t swing at everything

Cisco TalosBy Thorsten Rosendahl

Advisory

Our summary

Cisco Talos researchers have uncovered a new remote access trojan (RAT) named msaRAT, developed by the Chaos ransomware group. This Rust-based malware leverages the Chrome DevTools Protocol to create a stealthy command-and-control (C2) channel without direct network interaction. It begins with a deceptive MSI file posing as a Windows update, loading the payload into memory to facilitate ransomware deployment. The technique allows attackers to evade detection by routing traffic through legitimate browser processes. Organizations are advised to monitor for unusual curl commands, unauthorized MSI downloads, and signs of Chrome or Edge manipulation.

Read at Cisco Talos

Cisco Talos publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store