Skip to main content

Tag: chaos ransomware

4 articles

Person sitting at desk looks concerned, holding phone with blurred screen, while blurred figure looms in background.

Microsoft Teams Impersonation Attacks Deploy Chaos Ransomware

Cyber attackers are impersonating IT helpdesk staff on Microsoft Teams to trick employees into installing ransomware, with one financially motivated operation deploying Chaos ransomware in a matter of minutes. They use convincing voice calls and chats to gain remote access, often within just 2-3 minutes.

Analyst 207
Windows host computer on a cluttered desk with an open, idle browser window.

Chaos Ransomware Exploits Headless Browsers for Covert C2 Traffic

Cisco Talos uncovered a sneaky tactic used by Chaos Ransomware, where a Rust implant called msaRAT hijacks a victim's browser to disguise its communications, making it look like they're coming from a legitimate browser process. This clever trick lets the malware fly under the radar by using the Chrome DevTools Protocol to control the browser.

Analyst 207
Person sits at desk with laptop, surrounded by empty office space, browser window open.

Chaos Ransomware Gang Exploits Browsers for Stealthy C2 Communications

Cisco Talos researchers have uncovered a sneaky new backdoor, msaRAT, that hijacks Chrome or Microsoft Edge to secretly communicate with its command center, avoiding direct network connections. This stealthy tactic uses the browser's remote debugging interface to inject JavaScript and stay under the radar.

Analyst 207
Modern office interior with subtle hints of cyber activity in the background.

MuddyWater hackers exploit Chaos ransomware as cyber-espionage decoy

MuddyWater hackers have cleverly used Chaos ransomware as a decoy to mask their true intentions - and it's not about making a quick buck. Instead, their tactics suggest a more sinister goal, blurring the lines between state-sponsored espionage and cybercrime.

Analyst 207