BoletimSecJuly 24, 2026🇵🇹Translated from Portuguese

Chaos Ransomware Group Uses msaRAT Trojan to Hide C2 Traffic Through Invisible Chrome and Edge Browsers

The Chaos ransomware group has begun using a new trojan called msaRAT to hide its command-and-control communications inside legitimate connections made by Chrome and Edge browsers.

The malware was discovered on a compromised Windows system prior to the deployment of the ransomware encryptor. Written in Rust, msaRAT does not connect directly to the attackers' infrastructure. Instead, it starts a browser instance in invisible mode and controls it through the Chrome DevTools Protocol, ensuring that the process's network traffic remains limited to the local machine address.

The implant injects JavaScript code into the browser and uses a Cloudflare Workers service to negotiate a WebRTC connection. After negotiation, traffic is forwarded through Twilio TURN servers, preventing the real address of the attackers' servers from appearing in network logs. Received commands are executed via cmd.exe.

The malware also features queuing and flow-control mechanisms that support reliable transfer of files, screenshots, and other large data volumes. In the analyzed attack, operators downloaded an MSI installer presented as a Windows update. The package loaded a DLL containing msaRAT directly into memory, minimizing artifacts written to disk.

The technique does not exploit vulnerabilities in Chrome or Edge. Its goal is to make malicious traffic appear as normal browser activity and to leverage services that are widely permitted in corporate environments.

Related articles

BoletimSecRansomware & Extortion

Qilin Ransomware Operators Exploit Palo Alto PAN-OS VPN Flaw CVE-2026-0257

Operators linked to the Qilin ransomware group have been actively exploiting an authentication bypass vulnerability in Palo Alto Networks PAN-OS to gain initial access to corporate networks. The attacks, observed in June 2026, targeted the GlobalProtect VPN service running on Palo Alto firewalls and were tracked under CVE-2026-0257. Attackers used specially crafted authentication cookies to establish unauthorized VPN sessions, after which they harvested credentials from Windows LSASS processes and Active Directory NTDS databases. Lateral movement relied heavily on PsExec and administrative shares, supplemented by tools such as AnyDesk, Ngrok, LogMeIn, and NetExec. Before deploying the ransomware binary stored as win.exe in C:\PerfLogs\, the threat actors disabled Microsoft Defender real-time protection and cleared event logs. The vulnerability affects PAN-OS versions 10.2, 11.1, 11.2, and 12.1 as well as certain Prisma Access editions, while Panorama and Cloud NGFW remain unaffected.

BoletimSecRansomware & Extortion

Ransomware Attack Hits Coca-Cola Subsidiary Fairlife, Temporarily Halting US Production Systems

Fairlife, a company owned by Coca-Cola, temporarily suspended production operations in the United States after detecting unauthorized access to parts of its systems in a ransomware incident. The breach, publicly disclosed by Coca-Cola on July 16, 2026, affected environments directly linked to industrial production, prompting an immediate shutdown while investigations and recovery efforts continue. Fairlife manufactures milk, protein beverages, and other dairy products sold across the North American market, making the incident potentially disruptive to product availability, logistics, and internal processes. The company activated its incident response and business continuity protocols and engaged external cybersecurity specialists and consultants to assist with containment, investigation, and system restoration. No information has yet been released regarding data exfiltration, file encryption, or ransom demands, and the full scope of the attack remains under assessment. Coca-Cola has notified law enforcement authorities about the incident, while operations at Fairlife facilities in Canada were confirmed to be unaffected.

securitylab_nRansomware & Extortion

Six Weeks of Inactivity and 37 Years of History Lost: Cyberattack Forces German Textile Firm ZEGO into Bankruptcy

A prolonged cyberattack that halted operations for nearly six weeks has driven the Bavarian textile company ZEGO Textilveredelungszentrum into insolvency proceedings, ending 37 years of business activity. The firm, which specialized in fabric finishing and processing for the automotive sector, workwear producers, and technical textiles, was unable to recover from the severe financial strain caused by the production standstill that began after the incident on 29 March 2026. Managing Director Johannes Zenglein described the decision to seek creditor protection as one of the most difficult in the company’s history, noting that the financial burden had become insurmountable. Although the company has not disclosed whether ransomware was involved or whether attackers accessed customer or employee data, it confirmed that the operational shutdown alone pushed the business to the brink of collapse. ZEGO now hopes to continue limited production while insolvency administrators explore restructuring options to preserve jobs and relationships with clients and suppliers. The case echoes other high-profile incidents, such as the bankruptcy of British logistics company KNP Logistics after 158 years of operation following a ransomware attack that encrypted its systems.