Skip to content
Auto-CTI
Back to all actors

Chaos

Unknown Dormant
Mentions
2
First seen
23 Jul 2026
Last seen
23 Jul 2026

Relevant to you · Relevant

Threat focus:
ransomware

Origin

Unattributed

Profile

The Chaos ransomware group uses msaRAT to route command-and-control traffic through headless Chrome and Edge browsers. This creates a covert C2 channel that disguises itself as normal browser traffic. It enables undetected control of the infection. The technique leverages legitimate browser processes for concealment.

Affected vendors

MicrosoftGoogle

Associated malware / tools

Chaos ransomwaremsaRATChaos

Related actors

Share a CVE, technique or malware with this actor.

Activity (8 weeks)

31
32
33
34
35
36
37
38

Recent activity

ESC