New msaRAT malware uses Chrome and Edge browsers to conceal command-and-control traffic

The United States has reignited tensions in the Middle East by reimposing a naval blockade on Iranian ports.

The newly discovered malware represents an evolution in stealth techniques used by cybercriminals. Instead of establishing a direct network connection with attacker-controlled infrastructure, msaRAT leverages trusted browser processes to relay malicious traffic, making it significantly more difficult for traditional security tools to identify suspicious activity.

According to researchers, the malware is written in Rust, a modern programming language increasingly favored by threat actors due to its performance, cross-platform capabilities, and resistance to reverse engineering. Rust-based malware has become more common in recent years as cybercriminals seek to bypass conventional detection mechanisms.

A key feature of msaRAT is its use of the Chrome DevTools Protocol (CDP), a legitimate interface designed for debugging and automating Chromium-based browsers. The malware launches a headless instance of Google Chrome or Microsoft Edge and uses CDP commands to control the browser remotely. Through this browser session, it establishes encrypted communication with the attacker’s infrastructure.

Because all network traffic is generated by the trusted browser process, the malware avoids creating any direct outbound connections to its command-and-control servers. This tactic enables malicious communications to blend in with normal web browsing activity, reducing the likelihood of detection by endpoint security software, firewalls, and network monitoring systems.

Security analysts say this browser-based communication method presents a growing challenge for defenders. Many organizations rely on identifying unusual network connections or suspicious processes to detect malware infections. By abusing legitimate browser functionality, msaRAT can bypass many of these security controls while maintaining persistent access to compromised systems.

The Chaos ransomware group has been linked to multiple cyberattacks targeting organizations across various sectors. Researchers believe the deployment of msaRAT reflects the group’s continued investment in developing advanced tools capable of supporting ransomware operations, credential theft, reconnaissance, and long-term persistence within victim networks.

Cybersecurity experts recommend that organizations keep browsers and operating systems fully updated, monitor the misuse of browser debugging features such as the Chrome DevTools Protocol, restrict unnecessary browser automation capabilities, and deploy behavior-based endpoint detection and response (EDR) solutions capable of identifying anomalous browser activity.

The discovery of msaRAT underscores the growing sophistication of modern cyber threats and highlights how attackers are increasingly exploiting legitimate software features to evade detection. As browser-based malware techniques continue to evolve, security professionals warn that organizations must adopt advanced behavioral monitoring and proactive threat-hunting strategies to defend against these emerging attack methods.

Irfan Latif

Irfan Latif