CybersecurityJuly 23, 2026· via BleepingComputer

msaRAT malware hijacks Chrome and Edge to mask attacks

msaRAT malware hijacks Chrome and Edge to mask attacks

Image : BleepingComputer

A previously unknown backdoor named msaRAT is now circulating in the wild, giving the Chaos ransomware gang a stealthy way to exfiltrate data and receive commands without tripping network defenses.

Researchers tracking the operation noticed that msaRAT piggybacks on Google Chrome or Microsoft Edge to ferry its command-and-control traffic. By masquerading as legitimate browser traffic, the malware evades firewalls and intrusion-detection systems that would otherwise flag raw C2 beacons.

Under the browser’s hood

Once msaRAT gains a foothold on a host, it installs a browser extension and configures Chrome or Edge to proxy its outbound connections. The extension injects JavaScript that rewrites traffic on the fly, ensuring that all C2 exchanges look like routine web requests to popular domains. Because the requests emerge from the same processes that handle normal browsing, automated tools struggle to separate malicious packets from benign ones.

What to watch for

Early indicators show that msaRAT is delivered via spear-phishing emails containing weaponized documents. Organizations should review email filtering rules, disable unsigned browser extensions, and monitor for unusual process trees involving Chrome or Edge child processes.

Why it matters

msaRAT demonstrates how attackers continue to weaponize everyday software to bypass security controls. For defenders, the shift from raw C2 channels to browser-based tunnels means traditional network monitoring must now account for application-layer traffic patterns. The technique also underscores the importance of endpoint hardening—especially around browser extensions and macro-laden documents—if ransomware gangs are to be kept at bay.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home