Tag: chaos ransomware
4 articles

Microsoft Teams Impersonation Attacks Deploy Chaos Ransomware
Cyber attackers are impersonating IT helpdesk staff on Microsoft Teams to trick employees into installing ransomware, with one financially motivated operation deploying Chaos ransomware in a matter of minutes. They use convincing voice calls and chats to gain remote access, often within just 2-3 minutes.

Chaos Ransomware Exploits Headless Browsers for Covert C2 Traffic
Cisco Talos uncovered a sneaky tactic used by Chaos Ransomware, where a Rust implant called msaRAT hijacks a victim's browser to disguise its communications, making it look like they're coming from a legitimate browser process. This clever trick lets the malware fly under the radar by using the Chrome DevTools Protocol to control the browser.

Chaos Ransomware Gang Exploits Browsers for Stealthy C2 Communications
Cisco Talos researchers have uncovered a sneaky new backdoor, msaRAT, that hijacks Chrome or Microsoft Edge to secretly communicate with its command center, avoiding direct network connections. This stealthy tactic uses the browser's remote debugging interface to inject JavaScript and stay under the radar.

MuddyWater hackers exploit Chaos ransomware as cyber-espionage decoy
MuddyWater hackers have cleverly used Chaos ransomware as a decoy to mask their true intentions - and it's not about making a quick buck. Instead, their tactics suggest a more sinister goal, blurring the lines between state-sponsored espionage and cybercrime.