Fri, 24 Jul
34°C

New Delhi

Partly Cloudy
Feels Like
38°C
Humidity
62%
Wind Speed
14 km/h
Visibility
8 km
UV Index
8 (Moderate)
Pressure
1008 hPa
Hourly Forecast
3:00
34°C
20%
4:00
34°C
25%
5:00
33°C
30%
6:00
33°C
35%
7:00
32°C
40%
8:00
32°C
45%
7-Day Forecast
Today
Partly Cloudy
26°C
35°C
Sat
Partly Cloudy
26°C
35°C
Sun
Partly Cloudy
26°C
35°C
Mon
Partly Cloudy
26°C
34°C
Tue
Partly Cloudy
27°C
34°C
Wed
Partly Cloudy
27°C
34°C
Thu
Partly Cloudy
27°C
33°C
Daily News Insights LogoDaily News Insights Logo
BREAKING
Daily News Insights: AI-Powered News Platform — Updated On DemandBreaking coverage from India and the world, synthesized by Gemini 1.5 FlashLive pipeline: Firecrawl extraction • Supabase storage • Upstash caching
Home/Tech

Chaos Ransomware Hijacks Chrome and Edge to Build Invisible Attack Channels

DNI
Daily News Insights Editorial Desk
FRIDAY, 24 JULY 2026 AT 10:31 AM·4 MIN READ
Chaos Ransomware Hijacks Chrome and Edge to Build Invisible Attack Channels
Wikimedia
IMAGE: DAILY NEWS INSIGHTS / NEWS DATA LABS

DNI SUMMARY — KEY POINTS

  • The sophisticated msaRAT malware is now leveraging legitimate web browsers like Chrome and Edge to establish covert command and control communication channels.
  • Security researchers at Cisco Talos identified this novel technique, which allows the Chaos ransomware variant to bypass traditional network monitoring and detection systems.
  • By masquerading malicious traffic within routine browser requests, attackers can maintain persistent access to compromised machines while remaining undetected by standard security software.
  • This shift toward living off the browser represents a significant evolution in ransomware tactics, forcing cybersecurity teams to rethink their defensive strategies against modern threats.
  • Organizations must prioritize advanced endpoint monitoring and behavioral analysis to identify these subtle anomalies that hide in plain sight during normal web activity.
IN-DEPTH ANALYSIS
TechBusiness

Security researchers have uncovered a concerning development where the Chaos ransomware family utilizes a malicious agent known as msaRAT to conduct its operations. By exploiting the inherent trust placed in web browsers, attackers have successfully created an invisible command and control channel that effectively hides within standard traffic. This method signifies a departure from traditional malware techniques that often rely on isolated network sockets. By embedding communications within the browser process, the malware forces security tools to distinguish between legitimate user navigation and illicit data exfiltration.

Browser Exploitation Techniques Revealed

Browser Exploitation Techniques Revealed

The core of this operation relies on the ability of msaRAT to intercept and redirect traffic through the browser rather than initiating its own network connections. This approach allows the malware to piggyback on established, encrypted sessions that are typically ignored by firewalls and intrusion detection systems. Security experts have noted that because browsers like Google Chrome and Microsoft Edge are essential for daily productivity, their traffic is rarely subjected to the same level of granular scrutiny applied to secondary applications, providing hackers with a perfect cover for their activities.

The msaRAT malware disguises its command and control traffic by routing it directly through active browser processes on the host machine.

Security Analysts Track Evolving Threats

Traditional security mechanisms often struggle to categorize traffic generated by web browsers due to the massive volume and diversity of data involved in modern web browsing. The malicious code effectively exploits this blind spot, ensuring that its heartbeat signals and data transfers remain indistinguishable from typical user behavior. This creates a difficult challenge for IT administrators tasked with monitoring organizational networks. If a browser appears to be the source of a request, many automated systems will whitelist it, allowing the malicious communication to proceed without triggering any alarms or alerts.

Security Analysts Track Evolving Threats

New Defensive Priorities for Administrators

Analysis provided by Cisco Talos indicates that the integration of this browser-based communication is part of a broader trend where ransomware operators prioritize stealth over speed. By maintaining a low profile, these groups can persist within a network for extended periods, gathering intelligence and mapping internal assets before launching a full-scale encryption attack. This methodical approach highlights the shift from opportunistic hacking to targeted, persistent campaigns that are significantly harder to remediate once they have successfully established a foothold within an enterprise environment.

Security analysts report that this technique allows ransomware to bypass traditional network security appliances that typically trust web browser traffic by default.

The implications for enterprise security are profound, as the reliance on browsers for nearly every corporate task has created a massive surface area for abuse. Organizations can no longer assume that browser traffic is benign simply because it originates from a known application. Instead, security teams are encouraged to deploy advanced Endpoint Detection and Response solutions that can inspect process-level behavior in addition to network traffic. Differentiating between a user visiting a standard website and a malware-infected process sending data requires sophisticated telemetry that captures the intent behind the connection.

Adapting to Advanced Threat Landscapes

New Defensive Priorities for Administrators

Mitigating this threat requires a multi-layered defense strategy that emphasizes behavior monitoring over simple signature-based detection. Because the malware adapts to the user's environment, static rules are insufficient to block the communication channels created by msaRAT. Companies should implement strict egress filtering and consider utilizing browser isolation technologies that sandbox web activity. By restricting the browser's ability to communicate with arbitrary external servers, organizations can neutralize the primary advantage that this specific ransomware variant seeks to exploit during its initial infection phase.

As cybercriminals continue to refine their methods, the evolution of browser-based command and control demonstrates the agility of modern threat actors. Ransomware developers are clearly investing in research and development to bypass current defenses, making the cycle of innovation an ongoing struggle for global security teams. Maintaining vigilance and keeping software updated is a baseline requirement, but the future of defense lies in the ability to identify anomalous patterns within legitimate system processes. Resilience in this digital age depends entirely on the speed at which organizations adapt to these emerging tactics.

KEY TAKEAWAYS

Cisco Talos researchers emphasized that the malware uses legitimate browser functions to hide its presence and maintain persistent access to the target system.

Effective defense against this threat requires advanced endpoint monitoring that can distinguish between human-initiated browsing activity and automated malicious communication sessions.

How do you feel about this story?

Share This Story

Choose a platform to share this article