Scrappy RAT Malware Targets Chrome And Edge Users

A new remote access trojan (RAT), identified as msaRAT, has emerged from the cybersecurity research team at Cisco Talos, raising significant concerns among experts due to its capability to facilitate ransomware installation on compromised systems. This malware is attributed to the Chaos ransomware group and is notably constructed using Rust, allowing it to exploit existing installations of Chrome or Edge (Chromium-based) browsers.

By leveraging standard communication methods utilized by these browsers, msaRAT cleverly disguises its traffic through Chrome’s DevTools Protocol. This enables command-and-control (C2) communications that evade detection by conventional anti-malware or antivirus solutions. Once the attackers successfully infiltrate a target network using msaRAT, a multitude of malicious activities can unfold.

The malware operates via a headless browser process, which means it runs invisibly without a user interface, thereby facilitating remote code execution on affected machines. In addition to paving the way for ransomware deployment by the Chaos group, msaRAT also poses risks for covert data theft and other malicious actions.

While the potential reach of msaRAT could encompass the entire user base of Microsoft Edge and Google Chrome, the Chaos ransomware group typically focuses on large organizations. Although individual users could also be at risk, Cisco Talos has not provided specific examples or an estimated scope of msaRAT attacks, instead highlighting its innovative approach and the challenges it presents for detection.

Importantly, msaRAT exemplifies post-compromise malware, meaning it is typically installed through phishing emails or malicious files. This characteristic renders it immune to mitigation through standard browser patches. Given its novel operational methods, traditional firewalls and network monitoring tools are likely to falter unless defenders are aware of the specific nature of this attack.

To guard against msaRAT, Cisco Talos recommends implementing the following SNORT rules (SIDs) to detect and block the malware:

  • Snort 2: 1:66840, 1:66841, 1:66839
  • Snort 3: 1:301587, 1:66839

Additionally, users can add the following ClamAV signature:

  • Win.Downloader.ChaosRaas-10060321-0

For manual searches or use with other tools, the only Indicators of Compromise (IoC) include traffic directed to the following destinations:

  • 172.86.126.18
  • is-01-ast.ols-img-12.workers.dev

While the likelihood of most users being targeted by such an attack is low, it is prudent for individuals associated with large enterprises to utilize this information effectively or relay it to their IT departments. If msaRAT does infiltrate a system, the timeframe between its detection and the installation of ransomware is alarmingly short, and confidential data exfiltration may have already occurred.

Image Credit: Cisco Talos

Tech Optimizer
Scrappy RAT Malware Targets Chrome And Edge Users