Breaking
AviaMasters: Het Hoogvliegende Crash Game dat Spelers Alert HoudtPlay real money slots at Zizobet Casino: enjoy fast payouts and live actionThe Wellness of Tea Goes Beyond What’s in the CupAquaspins Casino: come sfruttare al meglio il bonus di benvenuto nel 2026Bursa Malaysia ends lower as selling pressure in oil-related counters weighs - The StarUCSI University strengthens global health and science diplomacy collaboration with UNU Global HealthAstro Celebrates 30th Anniversary With Free Access to All Channels and Exclusive Offers for CustomersJulia Farhana Initiates Divorce Proceedings Against Dr Che Hafiz After Seven Months of SeparationHarga tiket GP Bahrain di Sepang serendah RM200‘I Never Intended To Hurt Or Kill Rocky,’ Says Man Accused Of Animal CrueltyNo criminal or corruption elements found in KWAP investigationAdam Lee says old debts remain unpaid as new loans are taken.Malaysians To Receive Free 10GB Data From Five Telcos For Merdeka And Malaysia DayTEEAM at “Think Business, Think Hong Kong” SymposiumBrunei Darussalam Capital Market Development Seminar Series: An Introduction to Sukuk IssuanceOver 90% of UGM Educators Are Gemini Certified through Academic Upskilling InitiativeURIIS 2026 sasar percepat pengkomersialan inovasi universitiLelaki disyaki terjun sungai elak pemeriksaan polis ditemukan lemasBangladesh humble Australia with worst total in contest as Hasan takes 6-55How I Got My Career in Foreign Policy: Sadanand DhumeAviaMasters: Het Hoogvliegende Crash Game dat Spelers Alert HoudtPlay real money slots at Zizobet Casino: enjoy fast payouts and live actionThe Wellness of Tea Goes Beyond What’s in the CupAquaspins Casino: come sfruttare al meglio il bonus di benvenuto nel 2026Bursa Malaysia ends lower as selling pressure in oil-related counters weighs - The StarUCSI University strengthens global health and science diplomacy collaboration with UNU Global HealthAstro Celebrates 30th Anniversary With Free Access to All Channels and Exclusive Offers for CustomersJulia Farhana Initiates Divorce Proceedings Against Dr Che Hafiz After Seven Months of SeparationHarga tiket GP Bahrain di Sepang serendah RM200‘I Never Intended To Hurt Or Kill Rocky,’ Says Man Accused Of Animal CrueltyNo criminal or corruption elements found in KWAP investigationAdam Lee says old debts remain unpaid as new loans are taken.Malaysians To Receive Free 10GB Data From Five Telcos For Merdeka And Malaysia DayTEEAM at “Think Business, Think Hong Kong” SymposiumBrunei Darussalam Capital Market Development Seminar Series: An Introduction to Sukuk IssuanceOver 90% of UGM Educators Are Gemini Certified through Academic Upskilling InitiativeURIIS 2026 sasar percepat pengkomersialan inovasi universitiLelaki disyaki terjun sungai elak pemeriksaan polis ditemukan lemasBangladesh humble Australia with worst total in contest as Hasan takes 6-55How I Got My Career in Foreign Policy: Sadanand Dhume
Economy

Chaos ransomware group deploys new msaRAT tool to hijack browsers, Cisco Talos says

Cyber criminals behind the Chaos ransomware-as-a-service group are deploying a new Rust-based malware called msaRAT to build covert command-and-control channels through web browsers, cybersecurity research unit Cisco Talos reported.

Source: Cisco Talos Intelligence · July 25, 2026 at 11:33 PM · AI-assisted report

Chaos ransomware group deploys new msaRAT tool to hijack browsers, Cisco Talos says
Image: blog.talosintelligence.com

KUALA LUMPUR, 26 JULY 2026 —

Listen to this article

DomainFork Audio · read aloud

Cyber criminals behind the Chaos ransomware-as-a-service group are deploying a new Rust-based malware called msaRAT to build covert command-and-control channels through web browsers, cybersecurity research unit Cisco Talos reported.

Cisco Talos confirmed the Chaos group has been active since February 2025, consistently targeting large organizations using double extortion tactics. Attackers gain initial entry through spam emails and voice-based social engineering before establishing persistence on victim networks.

To deploy the new malware, attackers run a command to download a malicious installer named update_ms.msi into the victim's system directory, according to the research report. The installer disguises itself as a standard Windows update.

Cisco Talos noted that while the installer connects over port 443, the transmission occurs over plain HTTP. This method allows the payload to bypass perimeter firewalls that filter traffic by port number without inspecting protocol content.

Once executed, the installer extracts a dynamic link library named lib.dll directly into memory. Cisco Talos identified the underlying payload as msaRAT, a tool written in Rust that relies on the Tokio asynchronous runtime framework.

The Tokio framework allows the malware to handle multiple operations concurrently, such as receiving server frames and processing key exchanges, without blocking system processes.

After initializing, msaRAT searches the target machine for Google Chrome or Microsoft Edge and launches the browser in headless mode with remote debugging capabilities, Cisco Talos reported. The trojan then uses the Chrome DevTools Protocol to bypass Content Security

Malaysia Impact

Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.

Reporting based on Cisco Talos Intelligence. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.