New msaRAT malware hides C2 traffic via Chrome and Edge

Learn how the Chaos ransomware gang's new backdoor msaRAT uses Chrome and Edge browsers to disguise command-and-control traffic. Stay protected.

viernes, 24 de julio de 2026 • 4 min read • Q2BSTUDIO Team

msaRAT: backdoor que enruta C2 a través del navegador

In today's cybersecurity landscape, malicious actors are constantly innovating to bypass traditional defenses. Recently, the Chaos ransomware group introduced a new backdoor called msaRAT, which employs a particularly cunning technique: it uses the Chrome and Edge browsers as intermediaries to hide traffic to its command-and-control (C2) servers. This approach not only makes detection by perimeter security systems more difficult but also exploits the trust placed in legitimate system applications.

From a technical standpoint, msaRAT injects malicious code into browser processes, leveraging their network APIs to establish encrypted communications. In this way, C2 traffic blends with the user's normal HTTP/S requests, camouflaging itself as benign activity. Security analysts have observed that the malware can even modify the browser's proxy settings to redirect traffic without raising suspicion. This method represents a qualitative leap over previous techniques, such as using DNS tunnels or direct connections to suspicious IPs.

For businesses, this threat underscores the need to adopt a multi-layered security approach. Relying solely on firewalls or traditional antivirus solutions is no longer sufficient; it is essential to implement anomaly detection systems for application behavior and process control policies. In this context, having a technology partner like Q2BSTUDIO can make a difference. Our experience in custom software development allows us to create monitoring tools tailored to each organization's specific needs, integrating artificial intelligence capabilities to identify suspicious patterns in real time.

Cybersecurity is no longer an isolated department but a cross-functional function that must permeate all business processes. That is why at Q2BSTUDIO we offer cybersecurity and pentesting services that help companies assess their vulnerabilities and strengthen their defenses before an attack like msaRAT succeeds. Additionally, migrating to cloud environments such as AWS or Azure requires careful security planning, something we address in our cloud AWS and Azure services.

Chaos ransomware is not new, but the incorporation of msaRAT reveals an evolution in its tactics. Analysts have identified that the backdoor is primarily distributed through phishing campaigns using malicious Office documents or compressed files containing an executable. Once inside the system, msaRAT establishes persistence through modifications to the Windows registry and then communicates with the C2 using browsers. This communication may include downloading additional payloads, data exfiltration, or receiving instructions to launch the ransomware.

For organizations handling large volumes of data, business intelligence becomes a key ally in detecting anomalies. Combining BI and Power BI solutions with security systems makes it possible to correlate network events, application logs, and user behavior to identify signs of compromise. At Q2BSTUDIO, we develop customized dashboards that give security teams real-time visibility into the state of their systems, facilitating early response to threats like msaRAT.

Another vector to consider is process automation. Software process automation can help deploy security patches quickly and consistently, as well as orchestrate incident responses. For example, if anomalous browser behavior is detected, an automated system could immediately isolate the machine from the network. This rapid reaction capability is crucial for containing a ransomware spread.

Artificial intelligence, in turn, plays an increasingly important role in cybersecurity. Machine learning models can learn an organization's normal network traffic and detect deviations indicating the presence of msaRAT or similar threats. At Q2BSTUDIO, we are developing AI agents specialized in cybersecurity that analyze large volumes of data to provide contextual alerts and reduce false positives. These agents can integrate with the company's existing tools, improving the efficiency of the security team.

From a business perspective, investing in cybersecurity not only protects digital assets but also builds trust among customers and partners. A ransomware incident can paralyze operations, damage reputation, and incur millions in costs. Therefore, we recommend conducting regular security audits and updating incident response plans. At Q2BSTUDIO, we offer comprehensive services ranging from initial consulting to technical implementation, including staff training.

The case of msaRAT is a reminder that innovation in attack techniques is constant. Defenders must stay up to date and adopt tools and processes that allow them to anticipate threats. The combination of custom software, secure cloud services, artificial intelligence, and automation is the recipe for robust cybersecurity. At Q2BSTUDIO, we are committed to helping businesses navigate this complex environment, offering technology solutions that adapt to their needs and incorporate the latest security trends.

Finally, it's worth noting that detecting msaRAT is not trivial. We recommend using EDR (Endpoint Detection and Response) solutions that analyze process behavior, as well as monitoring network connections from browsers to suspicious domains. Companies can benefit from a proactive approach, such as the one we promote at Q2BSTUDIO, where we combine custom software development with advanced security practices. If your organization seeks protection against emerging threats, do not hesitate to contact us to explore how we can help strengthen your security posture.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.