Chaos
Unknown Dormant
- Mentions
- 2
- First seen
- 23 Jul 2026
- Last seen
- 23 Jul 2026
Relevant to you · Relevant
- Threat focus:
- ransomware
Origin
Unattributed
Profile
The Chaos ransomware group uses msaRAT to route command-and-control traffic through headless Chrome and Edge browsers. This creates a covert C2 channel that disguises itself as normal browser traffic. It enables undetected control of the infection. The technique leverages legitimate browser processes for concealment.
Affected vendors
MicrosoftGoogle
Associated malware / tools
Chaos ransomwaremsaRATChaos
Related actors
Share a CVE, technique or malware with this actor.