[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$foPTNv4bC553RIJLPlWNap_pLJgK74HbJpmHfJ5EPCOg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"3f22d286-030c-46ff-9546-9a77e2e31df4","chaos-ransomware-hides-c2-traffic-in-legitimate-browser-sessions-via-msarat","85b925c9-82a0-4819-b21e-1e4db859e76b","Chaos Ransomware Hides C2 Traffic in Legitimate Browser Sessions via msaRAT","The Chaos ransomware group has developed a sophisticated evasion technique by routing command-and-control traffic through the victim's own Chrome or Edge browsers running in headless mode, using the Chrome DevTools Protocol and WebRTC data channels relayed through Twilio's TURN service. Because the traffic originates from legitimate browser processes and passes through trusted platforms like Cloudflare and Twilio, traditional network-based detection tools struggle to distinguish malicious activity from normal web browsing. This matters because it fundamentally undermines perimeter-based security controls and signature-based detection, requiring defenders to adopt behavioral and process-level monitoring strategies. Organizations that rely solely on network traffic inspection without endpoint-level visibility will have little warning before ransomware payload delivery and encryption begins.","**Immediate actions:**\n- Deploy endpoint detection and response (EDR) tools that monitor for anomalous browser process behavior, including headless mode launches initiated by non-user processes.\n- Block or alert on outbound WebRTC and DevTools Protocol (port 9222) connections originating from non-standard parent processes.\n- Review and restrict which applications are permitted to invoke Chrome or Edge in headless mode via application allowlisting policies.\n\n**Detection measures:**\n- Instrument SIEM rules to flag browser processes spawned by unexpected parent executables (e.g., Rust binaries, unknown services).\n- Monitor DNS and TURN\u002FSTUN relay traffic to known third-party services (Twilio, Cloudflare) for abnormal volume or frequency from endpoints.\n- Establish behavioral baselines for browser process network activity to detect deviations indicative of C2 tunneling.\n\n**Long-term improvements:**\n- Implement strict network segmentation to limit lateral movement and restrict endpoints from initiating unsolicited outbound connections to relay services.\n- Adopt a Zero Trust architecture that continuously validates process identity and context before permitting outbound network communication.\n- Conduct regular threat hunting exercises focused on living-off-the-land and browser-abuse techniques to proactively surface novel evasion methods.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 8: Audit Log Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 SI-4: System Monitoring","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 AC-17: Remote Access","MITRE ATT&CK T1071.001: Application Layer Protocol – Web Protocols","MITRE ATT&CK T1219: Remote Access Software","MITRE ATT&CK T1090: Proxy","NIST CSF DE.CM-1: Network Communications Monitored","NIST CSF PR.PT-3: Least Functionality Principle","published","2026-07-23T16:22:04.453074+00:00","2026-07-23T16:22:04.374+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fchaos-ransomware-uses-msarat-to-route.html","chaos-ransomware-uses-msarat-to-route-c2-traffic-through-headless-chrome-and-edg-fafb91","Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]