Threat Alerts
Your place for the latest CyberProof cyber threat intelligence alerts and updates
Speak with an ExpertChaos Ransomware Deploys Browser Hijacking msaRAT for Stealthy Command and Control
Researchers have identified msaRAT, a new Rust-based remote access trojan (RAT) used by the Chaos ransomware group to establish stealthy command-and-control (C2) communications by abusing legitimate web browsers. Instead of communicating directly with attacker-controlled infrastructure, the malware launches a hidden Google Chrome or Microsoft Edge instance in headless mode and leverages the Chrome DevTools Protocol (CDP) and WebRTC to tunnel encrypted C2 traffic through legitimate browser activity. This technique enables the malware to blend into normal network traffic, significantly reducing the likelihood of detection by traditional network security solutions.
Following initial access through phishing, vishing, or remote management tool abuse, attackers deploy msaRAT to execute remote commands, establish persistence, and maintain covert access to compromised systems. The malware retrieves connection parameters from Cloudflare Workers, uses Google STUN services for network traversal, and relays communications through Twilio TURN servers, while adding an additional encryption layer over WebRTC traffic to further obscure malicious activity. By routing all external communications through a legitimate browser process instead of its own executable, msaRAT represents an advanced evolution in browser-assisted malware techniques, allowing the Chaos ransomware group to evade network monitoring and sustain long-term access before deploying ransomware.
AgentBaiting Campaign Targets AI Development Platforms
The AgentBaiting campaign has been observed abusing the growing AI ecosystem by distributing malware through more than 800 fake AI Skills and Model Context Protocol (MCP) servers hosted in malicious GitHub repositories. As part of the broader FakeGit operation, researchers identified approximately 7,600 malicious repositories created by over 6,600 fake developer accounts, impersonating legitimate AI tools, enterprise integrations and developer utilities. By cloning trusted projects, creating convincing documentation and leveraging public AI registries, the attackers increased the likelihood that both developers and AI assistants would recommend and install the malicious repositories.
Victims downloading the advertised AI Skills or MCP servers instead received malicious ZIP archives that executed SmartLoader, a multi-stage malware loader capable of establishing persistence, retrieving additional payloads and deploying the StealC information stealer. Researchers also demonstrated that AI assistants, including Claude Code, Gemini and ChatGPT, could surface these malicious repositories during tool discovery, potentially directing users toward attacker-controlled installation instructions. The campaign highlights a new evolution of software supply chain attacks, where threat actors exploit trusted AI development workflows and public capability marketplaces to distribute malware and harvest sensitive credentials and session data from developer environments.
Public PoC Released for High-Severity Active Directory Certificate Services Vulnerability
Researchers have published a proof-of-concept exploit for CVE-2026-54121 (CVSS 8.8), a high-severty improper authorization vulnerability in Microsoft Active Directory Certificate Services (AD CS), dubbed Certighost. The flaw allows a low-privileged domain user to obtain a certificate for a legitimate Domain Controller by abusing the AD CS certificate enrollment process, enabling authentication as the Domain Controller without requiring administrative privileges.
Successful exploitation can enable attackers to perform DCSync attacks, retrieve sensitive Active Directory secrets such as the krbtgt account hash, and ultimately achieve full domain compromise. Exploitation requires a vulnerable Enterprise CA configuration, network access, and a valid domain account.
Starland RAT Distributed via Trojanized Installers
A financially motivated actor is distributing a Python-based remote access trojan named Starland via trojanized installers bundled with legitimate apps (WebEx, Zoom, MobaXterm, DBeaver, FACEIT), enabling credential and cryptocurrency theft and persistent remote access.
The multi-stage chain frequently begins with an HTA delivered through ClickFix-style prompts that runs via mshta.exe. The HTA retrieves an NSIS trojanized installer that bundles pythonw.exe and a compiled loader disguised as LICENSE.txt; the loader XOR-decrypts and executes Starland in memory. Starland performs anti-analysis checks, establishes persistence, scheduled tasks and Startup LNKs, attempts UAC elevation, performs host and Active Directory reconnaissance, enumerates browser and desktop/extension cryptocurrency wallets, captures screenshots, and can stage shellcode or download additional payloads.
Command-and-control uses a hardcoded C2 with a blockchain-anchored fallback retrieved via a Polygon JSON-RPC call and sends execution beacons to Telegram bots. A separate PowerShell in-memory C2 implant implements encrypted beaconing, HWID binding, and a Runspace task engine to deliver further scripts. Successful compromises can yield long-lived remote access, credential and wallet theft, reconnaissance of domain environments, and follow-on payload execution while minimizing disk artifacts and complicating detection.
Critical Zoom Windows Account Takeover Vulnerability
A critical Windows vulnerability in Zoom clients can allow unauthenticated attackers to hijack user accounts over the network, creating high-impact risks to confidentiality, integrity, and availability of affected endpoints and corporate accounts.
The flaw, tracked as CVE-2026-53412(CVSS Score 9.8), stems from improper input validation in Windows Zoom Desktop/Workplace and certain VDI client builds and can be exploited via network access to perform account takeover without prior authentication. Multiple Windows branches and legacy client versions are affected.
ACR Stealer Abuses WebDAV Shares and ClickFix for Credential Theft
ACR Stealer is an information-stealing malware family that targets Windows systems to steal credentials, browser session cookies, and other sensitive data while establishing persistent remote access. Successful compromise enables account takeover, unauthorized access to enterprise applications, and provides a foothold for additional payload deployment or follow-on intrusion activity. Recent campaigns have increasingly targeted enterprise environments using ClickFix-themed social engineering and trusted Windows components to evade detection.
The attack chain begins with ClickFix lures directing victims to attacker-controlled WebDAV shares, where malicious DLLs are executed directly from the remote location through the legitimate Windows utility rundll32.exe, eliminating the need to stage a traditional executable on disk. Execution deploys Python-based loaders that retrieve additional payloads, establish encrypted command-and-control communications, and exfiltrate credentials, browser session cookies, and other collected information





