Chaos ransomware group deploys new msaRAT tool to hijack browsers, Cisco Talos says
Cyber criminals behind the Chaos ransomware-as-a-service group are deploying a new Rust-based malware called msaRAT to build covert command-and-control channels through web browsers, cybersecurity research unit Cisco Talos reported.
Source: Cisco Talos Intelligence · July 25, 2026 at 11:33 PM · AI-assisted report

KUALA LUMPUR, 26 JULY 2026 —
Listen to this article
DomainFork Audio · read aloud
Cyber criminals behind the Chaos ransomware-as-a-service group are deploying a new Rust-based malware called msaRAT to build covert command-and-control channels through web browsers, cybersecurity research unit Cisco Talos reported.
Cisco Talos confirmed the Chaos group has been active since February 2025, consistently targeting large organizations using double extortion tactics. Attackers gain initial entry through spam emails and voice-based social engineering before establishing persistence on victim networks.
To deploy the new malware, attackers run a command to download a malicious installer named update_ms.msi into the victim's system directory, according to the research report. The installer disguises itself as a standard Windows update.
Cisco Talos noted that while the installer connects over port 443, the transmission occurs over plain HTTP. This method allows the payload to bypass perimeter firewalls that filter traffic by port number without inspecting protocol content.
Once executed, the installer extracts a dynamic link library named lib.dll directly into memory. Cisco Talos identified the underlying payload as msaRAT, a tool written in Rust that relies on the Tokio asynchronous runtime framework.
The Tokio framework allows the malware to handle multiple operations concurrently, such as receiving server frames and processing key exchanges, without blocking system processes.
After initializing, msaRAT searches the target machine for Google Chrome or Microsoft Edge and launches the browser in headless mode with remote debugging capabilities, Cisco Talos reported. The trojan then uses the Chrome DevTools Protocol to bypass Content Security
Malaysia Impact
Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.