Chaos 랜섬웨어가 msaRAT를 사용해 C2 트래픽을 헤드리스 브라우저를 통해 우회한다.
Chaos 랜섬웨어 그룹은 피해자의 브라우저를 통해 명령 및 제어를 실행했다. 이를 뒷받침하는 Rust 임플란트인 msaRAT가 감염된 Windows 머신에서 발견되었으며, 이 임플란트는 자체적으로 아웃바운드 연결을 열지 않는다. 대신 127.0.0.1와 통신하며, Chrome이나 Edge를 헤드리스 모드로 시작하여 브라우저를 조작한다.
Chaos ransomware uses msaRAT to route C2 traffic through the victim's headless browser.
The Chaos ransomware group ran its command-and-control through the victim's own browser. The Rust implant, msaRAT, was discovered on a compromised Windows machine before encryption began. This implant never opens an outbound connection on its own; it communicates with 127.0.0.1, starting Chrome or Edge in headless mode to drive the browser.