msaRAT is a Rust-based remote access trojan attributed to the Chaos ransomware group and observed in post-compromise activity prior to ransomware deployment. It is notable for delegating its external command-and-control communications to the victim’s own Chrome or Microsoft Edge browser rather than opening direct outbound connections from the malware process. The implant launches a headless browser with remote debugging enabled, connects to it over the Chrome DevTools Protocol, bypasses content security restrictions, and injects JavaScript that establishes a covert WebRTC DataChannel for command-and-control. Signaling is performed through a Cloudflare Workers endpoint, while relay traffic is forced through Twilio TURN infrastructure by omitting direct ICE candidates, helping conceal attacker infrastructure and making malicious traffic appear as ordinary browser activity. msaRAT applies layered encryption by combining browser-provided DTLS with an additional ChaCha-Poly1305 scheme using an ECDH-derived key. It supports remote command execution on compromised Windows systems and includes flow-control logic consistent with transferring larger payloads such as screenshots or files. Delivery observed in Chaos intrusions involved a fake software-update MSI that loaded the Rust payload directly into memory. Chaos operators have been associated with spam and voice-phishing initial access patterns, but msaRAT itself has been documented as a post-access implant used to maintain covert interactive control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On 23 July 2026, one day before TWINLOOT was compiled, Cisco Talos published their analysis of Chaos group’s msaRAT, which uses the same class of technique (headless browser + TURN relay) but routes through Twilio rather than Teams.
Then, late last month, another new Rust-based RAT dubbed msaRAT was observed using the same TURN method, but against Twilio instead of Teams.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Its operators commonly gain entry through spam emails and voice phishing, then use remote-management tools and legitimate file-sharing services to keep access and steal data.
The initial compromise occurred via social engineering on Microsoft Teams. An external actor impersonating IT support convinced a user to run a PowerShell command that downloaded an archive containing a staged Python 3.12.9 embeddable runtime and a 39 MB compiled payload.
The MSI impersonates a Windows update and loads the RAT DLL directly into memory via a custom installer action.
What a network defender sees on the wire is a browser process making HTTPS requests to Cloudflare and WebRTC traffic to Twilio’s relay service, both legitimate, both commonly allowed.
ou via les relais TURN de Microsoft Teams ... en utilisant des WebRTC DataChannels
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT mentioned as independently converging on similar techniques such as headless browser, CDP, and TURN relay usage.
A Rust-based RAT attributed to the Chaos ransomware group that uses a headless browser controlled through CDP, Cloudflare Workers for signaling, and Twilio TURN relays to establish a covert WebRTC DataChannel-based tunnel to the attacker's server.
A RAT attributed in the article to the Chaos group that uses a headless browser via CDP and TURN relay transport, cited here as a comparison to TWINLOOT’s technique.
Rust-based remote access trojan that uses the Chrome DevTools Protocol to manipulate the Chrome browser for command-and-control, avoiding direct network access by the malware binary itself. It performs SDP offer/answer signaling with an embedded Cloudflare Workers endpoint, establishes a WebRTC DataChannel to the C2 server, and uses Twilio TURN for NAT traversal and covert tunneling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.