Chaos Ransomware Hides Command-and-Control Inside Victims’ Own Browsers
The Chaos ransomware group has been found running its command-and-control communications through the victim’s own browser, using a Rust implant called msaRAT that never opens an outbound connection of its own, instead driving Chrome or Edge in headless mode over the browser’s own debugging API and relaying every message through a WebRTC data channel via Twilio’s TURN service. The technique means defenders inspecting network traffic see only a browser calling Cloudflare and Twilio, with the attacker’s own server address never appearing at all. The disclosure lands the same week two leaders of the Scattered Spider hacking group received 66-month jail sentences in Britain’s biggest cybercrime prosecution to date, and as new data shows Qilin and The Gentlemen locked in a genuine rivalry for the top ransomware attacker position of 2026.
Why Browser-Based Command-and-Control Is a Genuinely Clever Evasion
Cisco Talos’s detailed analysis of msaRAT reveals a genuinely sophisticated evasion architecture: rather than the implant itself communicating with attacker infrastructure, it drives a headless browser instance through the Chrome DevTools Protocol, the browser’s own legitimate debugging interface, and lets that browser instance handle all outbound communication through a WebRTC data channel relayed via Twilio’s TURN service. Since Twilio and Cloudflare are both broadly trusted, legitimate infrastructure providers, any network monitoring tool inspecting outbound traffic sees exactly what it would expect from ordinary, legitimate browser activity.
This technique represents a genuinely significant evasion advancement worth understanding in detail:- The implant process itself never makes outbound connections — msaRAT’s process communicates only with localhost, meaning process-level network monitoring would find nothing suspicious about the malware component itself
- Legitimate third-party infrastructure absorbs all detection risk — by routing traffic through Twilio’s TURN relay service, the actual command-and-control communication hides inside traffic to a service most organizations would never flag or block
- This joins a broader pattern of trust-exploitation techniques — this approach mirrors DragonForce’s earlier Backdoor.Turn technique hiding traffic inside Microsoft Teams relay infrastructure, reinforcing that hijacking legitimate, trusted communication channels has become a genuinely established ransomware evasion category, not an isolated novelty
Scattered Spider Leaders Receive 66-Month Sentences
Two leaders of the Scattered Spider hacking group received 66-month jail sentences in what prosecutors describe as Britain’s biggest cybercrime prosecution to date, following their disruption of London’s transport authority that caused $39 million in losses and recovery costs. Sentences of this length for a UK cybercrime prosecution represent a genuinely significant deterrent signal, particularly given Scattered Spider’s broader reputation for sophisticated social engineering attacks against major organizations across multiple countries throughout 2026.
Qilin and The Gentlemen Battle for Ransomware’s Top Spot
Qilin and The Gentlemen are locked in a genuine rivalry for the top ransomware attacker position in 2026, each overtaking the other throughout July, with industry trackers attributing the competitive dynamic partly to genuine rivalry between the two cybercriminal collectives. Both groups claimed nearly 300 victims in the second quarter alone, with total global ransomware volume rising roughly 20% year over year through the first half of 2026, alongside a striking 74% quarter-over-quarter jump in attacks against billion-dollar companies specifically, even as US-based small and mid-sized businesses continue absorbing the largest overall share of incidents from both groups.
The Gentlemen’s 90/10 affiliate revenue split, considerably more generous than the industry-standard 80/20 arrangement covered in previous weeks, likely continues fueling its ability to compete directly with Qilin for top-position status, illustrating how directly affiliate compensation structure can drive a ransomware operation’s overall growth trajectory.
Coca-Cola’s Fairlife Breach Gets Confirmed Attribution
The Anubis ransomware group listed Coca-Cola’s Fairlife dairy subsidiary on its leak website on July 20, just days after Coca-Cola’s July 16 Form 8-K filing disclosed the initial breach, confirming attackers reached parts of Fairlife’s production-related environment while Canadian operations continued unaffected. Coca-Cola stated product safety and quality were not affected, and the company activated its incident response plan while engaging outside cybersecurity advisors and law enforcement, a genuinely appropriate, well-documented response sequence for an incident of this scale and public company disclosure significance.
What Organizations Should Do Now
Given msaRAT’s demonstrated technique, security teams should specifically monitor for unusual headless browser process activity and Chrome DevTools Protocol usage on endpoints, since traditional network-layer monitoring alone will not catch this specific evasion technique given how convincingly it mimics legitimate browser-to-cloud-service traffic. Organizations should treat Scattered Spider’s 66-month sentences as reinforcement that sophisticated social engineering campaigns targeting major infrastructure carry genuine, substantial legal consequences when successfully prosecuted. And organizations across all sectors, particularly billion-dollar companies given the 74% quarter-over-quarter attack increase against this category, should treat the Qilin-Gentlemen rivalry as confirmation that ransomware targeting intensity continues escalating rather than stabilizing, warranting continued investment in both identity-focused and network-evasion-aware detection capability.
msaRAT’s browser-hijacking command-and-control technique represents a genuinely clever evolution in ransomware evasion, hiding malicious communication inside the exact trusted infrastructure, browsers, Cloudflare, Twilio, that most organizations would never think to scrutinize. As Qilin and The Gentlemen’s rivalry continues driving overall ransomware volume higher, defenders should expect this kind of trust-exploitation evasion technique to keep spreading across the broader ransomware ecosystem.
Published by MAJ.COM AI Autonomous
Email: Support@MAJ.COM
Website: https://QUE.COM Intelligence | Sponsored by https://MAJ.COM Automate Your Business. Multiple Your Revenue.
Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous
Discover more from QUE.com
Subscribe to get the latest posts sent to your email.
