Thursday, July 23, 2026
NewsezeNews with Rewards · Earn while you read
+5 credits / query
cyber

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

Newseze Wire·Thu, Jul 23, 1:11 PMWire: The Hacker News
Open original source Read full story (in-site)
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.

Sourcing & attribution. Newseze provides AI-curated summaries, narrative framing, and editorial analysis. The underlying reporting was contributed by The Hacker News; tap “Open original source” above to read their full reporting and support the contributing newsroom directly.

Newseze Analysis97 words · original commentary · full read loading…
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The story falls into Newseze's cyber desk and is being actively tracked by our editorial team. Calm framing, primary-source references, and respectful tone — every Newseze story is scored for drama and conspiracy before it reaches you. Worth knowing: Newseze refreshes its newsroom every hour and flags fast-moving local and breaking news as it develops. Watch this page for updates. Reporting: The Hacker News.
Ask Us · Any Story, Any AnswerBe the first to ask

Newseze's algorithm reads the story and answers your question — calmly, factually, with source attribution. No comments, no flame wars — just answers.

No questions yet. Be the first.

Answers reflect Newseze's editorial framework applied under fair use (17 U.S.C. § 107). Not financial, legal, medical, or tax advice. Hate speech and racial slurs are blocked.

Related stories

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
CYBERtrust 78
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Why it mattersAn exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a pre…

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and educ…

ChellaBy Chella·4h ago
WireThe Hacker News
Full Analysis Comment PostRead →
How Synthetic Identity Fraud is Coming for Machine Identities
CYBERtrust 78
How Synthetic Identity Fraud is Coming for Machine Identities

Why it mattersMost people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch.

Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much har…

ChellaBy Chella·4h ago
WireThe Hacker News
Full Analysis Comment PostRead →
CISA Flags Two Active Vulnerabilities as Exploit Targets for U.S. Systems
CYBERtrust 91
CISA Flags Two Active Vulnerabilities as Exploit Targets for U.S. Systems

Why it mattersCISA's addition of vulnerabilities to its Known Exploited Vulnerabilities catalog signals which threats are actively weaponized in the wild, giving enterprises and federal agencies clear priority targets for immediate pa…

CISA Adds Two Known Exploited Vulnerabilities to Catalog    CISA (.gov)

ChellaBy Chella·1d ago
WireCISA Alerts via Google News
Full Analysis Comment PostRead →