top of page
ALL POSTS
Chaos Ransomware's msaRAT: Leveraging Browser-Based Covert C2 Channels to Evade Detection
Key Findings Cisco Talos discovered msaRAT, a Rust-based remote access trojan used by the Chaos ransomware group that routes all command-and-control traffic through Chrome or Edge browsers The malware never makes direct network connections; it exclusively uses Chrome DevTools Protocol (CDP) to manipulate the victim's browser for C2 communications msaRAT establishes WebRTC DataChannels through Cloudflare Workers for signaling and Twilio TURN relays for actual C2 traffic, makin
Jul 233 min read
DragonForce Ransomware Exploits Microsoft Teams Relays to Conceal Malicious Command-and-Control Traffic
Key Findings DragonForce ransomware operators deployed Backdoor.Turn, a custom Go-based remote access trojan that conceals command-and-control traffic within Microsoft Teams relay infrastructure This marks the first publicly documented abuse of Microsoft's TURN relay servers by threat actors Attackers maintained network access for one to two months while evading detection by routing malicious traffic through legitimate Microsoft servers The group employed sophisticated defens
Jun 183 min read
bottom of page
