DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // CHAOS-RANSOMWARE-MSARATFIRST SEEN: FEB 2025

CHAOS RANSOMWARE GROUP

ALSO KNOWN AS: Chaos RaaS
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:FEB 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL69/100
RESOURCES69/100
PERSISTENCE72/100
STEALTH64/100
IMPACT78/100

Chaos is a RaaS group confirmed active since February 2025 that has now introduced msaRAT, a novel Rust-based RAT discovered and detailed by Cisco Talos on July 23, 2026. msaRAT routes all C2 traffic exclusively through the victim's own Chrome or Edge browser via the Chrome DevTools Protocol (CDP), meaning the malware process itself never makes a direct network connection — defenders see only legitimate browser traffic to Cloudflare and Twilio, not attacker infrastructure. This 'living off the browser' technique represents a significant evasion advance over traditional C2 methods.

Financial — ransomware deployment and double extortion against large organizations

Vishing (voice phishing) initial access, spam email phishing, RMM tool abuse for persistence, legitimate file-sharing service abuse for data staging, Rust-based implant (msaRAT), Chrome DevTools Protocol (CDP) C2 tunneling, headless browser hijacking (Chrome/Edge), WebRTC data channel over Twilio TURN relay, fake Windows Update MSI dropper, double extortion

ENTERPRISE
HEALTHCARE
FINANCE
TECHNOLOGY

msaRAT Rust implant delivered via update_ms.msi over port 443; C2 routed through victim's headless Chrome/Edge browser via CDP; Cloudflare Workers endpoint used as relay; Twilio TURN service for WebRTC data channel; legitimate RMM platforms for persistence

FILE DATE: FEB 2025
Initial RaaS Operations
Chaos confirmed active as a RaaS using vishing and spam email for initial access, targeting large organizations with double-extortion ransomware.
FILE DATE: JUL 2026
msaRAT Browser-Based C2 Deployment
Cisco Talos disclosed msaRAT on July 23, 2026 — a Rust ███████████████ a pre-encryption stage tool that routes C2 entirely through the victim's browser via CDP and WebRTC, making attacker traffic indistinguishable from legitimate browser activity on the wire.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn