SUBJECT PROFILE
Chaos is a RaaS group confirmed active since February 2025 that has now introduced msaRAT, a novel Rust-based RAT discovered and detailed by Cisco Talos on July 23, 2026. msaRAT routes all C2 traffic exclusively through the victim's own Chrome or Edge browser via the Chrome DevTools Protocol (CDP), meaning the malware process itself never makes a direct network connection — defenders see only legitimate browser traffic to Cloudflare and Twilio, not attacker infrastructure. This 'living off the browser' technique represents a significant evasion advance over traditional C2 methods.
Financial — ransomware deployment and double extortion against large organizations
OPERATIONAL HISTORY
Vishing (voice phishing) initial access, spam email phishing, RMM tool abuse for persistence, legitimate file-sharing service abuse for data staging, Rust-based implant (msaRAT), Chrome DevTools Protocol (CDP) C2 tunneling, headless browser hijacking (Chrome/Edge), WebRTC data channel over Twilio TURN relay, fake Windows Update MSI dropper, double extortion
KNOWN INFRASTRUCTURE
msaRAT Rust implant delivered via update_ms.msi over port 443; C2 routed through victim's headless Chrome/Edge browser via CDP; Cloudflare Workers endpoint used as relay; Twilio TURN service for WebRTC data channel; legitimate RMM platforms for persistence