How to get rid of msaRAT malware

Trojan

Also Known As: msaRAT remote access trojan

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What kind of malware is msaRAT?

msaRAT is a Remote Access Trojan (RAT) written in the Rust programming language, linked to the Chaos ransomware group. According to research published by Talos Intelligence, it uses an unusual "living off the browser" technique to keep its communications with the attacker's server hidden.

Rather than making network connections on its own, msaRAT takes control of a Chrome or Edge browser already installed on the victim's machine and routes all attacker traffic through it. This makes the malware's activity look like ordinary browser usage, which is considerably harder for security tools to detect.

The RAT is delivered as an MSI installer that impersonates a routine Windows update. Victims typically notice nothing unusual at the point of infection.

msaRAT RAT detections on VirusTotal

msaRAT overview

Once the installer runs, msaRAT loads its payload directly into memory and searches for a Chrome or Edge browser on the system using environment variable checks and Windows Registry queries. Once located, the browser is launched silently in headless mode with remote debugging enabled.

With the browser under its control, msaRAT can capture screenshots of the victim's screen, execute commands on the machine, and send files back to the attacker. The connection is persistent, meaning the attacker retains access to the infected machine and can issue new instructions at any time.

The "living off the browser" technique

msaRAT communicates with the attacker's server by sending instructions to the hijacked browser using Chrome DevTools Protocol (CDP), a built-in debugging interface present in Chrome and Edge. The browser then injects JavaScript into its own session and opens an encrypted data channel to the attacker.

The data channel is built on WebRTC - a technology browsers normally use for video calls and file sharing. msaRAT forces all traffic through a Twilio relay server, so the attacker's real IP address never appears directly in network logs.

Traffic also passes through Cloudflare's infrastructure, masking its origin further. The communications themselves are protected by two encryption layers: WebRTC provides one automatically, and msaRAT adds a second using ChaCha20-Poly1305 with keys negotiated via Elliptic-curve Diffie-Hellman.

How msaRAT avoids detection

Because all outbound connections appear to come from the browser process and not from the malware itself, security tools that monitor unknown programs making external connections will not observe msaRAT directly on the network. The real attacker infrastructure is hidden behind Cloudflare's content delivery network and Twilio's relay servers.

msaRAT also disables Content Security Policy in the browser session it controls via a CDP command, and spoofs HTTP request headers to make traffic appear to originate from a Microsoft service. HTTP traffic is sent over port 443, the port normally associated with HTTPS, which can help it slip past firewalls that check port numbers rather than actual protocols.

Threat Summary:
Name msaRAT remote access trojan
Threat Type Remote Access Trojan (RAT)
Symptoms Remote Access Trojans are designed to stealthily infiltrate the victim's computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine.
Distribution methods Malicious MSI installer, fake Windows update notifications, spam emails, social engineering.
Damage Stolen passwords and banking information, identity theft, the victim's computer added to a botnet, additional infections, monetary loss, account hijacking.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Conclusion

msaRAT is a technically sophisticated RAT used by the Chaos ransomware group to maintain covert remote access to infected machines. Its browser-based C2 technique makes it considerably harder to detect than conventional RATs, as all traffic appears to come from a legitimate browser rather than from the malware itself.

An infection puts victims at risk of data theft, remote surveillance, and the deployment of additional payloads, including ransomware. The malware should be removed from any affected system without delay. More examples of RATs are Dolphin X, MarkiRAT, and Starland.

How did msaRAT infiltrate my computer?

According to Talos Intelligence, msaRAT is delivered as an MSI installer file named update_ms.msi. It is downloaded via a curl command over HTTP on port 443 and disguised as a routine Windows update, which reduces the victim's suspicion at the moment of installation. Once the installer runs, the RAT payload is loaded directly into memory.

The Chaos group, active since February 2025, targets large organizations and threatens to both encrypt their data and leak it publicly unless a ransom is paid. The group has been observed gaining initial access through spam emails and voice phishing calls, with remote management tools used to maintain persistence and legitimate file-sharing services used to exfiltrate stolen data.

More broadly, RATs and similar threats reach victims through phishing emails with malicious attachments, fake software download pages, pirated software and software 'cracks', malicious advertisements, and infected removable storage devices. Downloading software only from official sources significantly lowers the risk of infection.

How to avoid installation of malware?

Be cautious with any unexpected email, particularly one containing an attachment or link. Even messages that appear to come from a trusted sender can be spoofed. Download programs only from official developer websites or trusted app stores, and avoid pirated software, 'cracks', and key generators.

Keep your operating system and all installed applications up to date to close known security vulnerabilities. Use reputable security software and run regular scans. If you believe that your computer is already infected, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Quick menu:

How to remove malware manually?

Manual malware removal is a complicated task - usually it is best to allow antivirus or anti-malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for Windows.

If you wish to remove malware manually, the first step is to identify the name of the malware that you are trying to remove. Here is an example of a suspicious program running on a user's computer:

Malware process running in the Task Manager

If you checked the list of programs running on your computer, for example, using task manager, and identified a program that looks suspicious, you should continue with these steps:

manual malware removal step 1Download a program called Autoruns. This program shows auto-start applications, Registry, and file system locations:

Autoruns application appearance

manual malware removal step 2Restart your computer into Safe Mode:

Windows XP and Windows 7 users: Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK. During your computer start process, press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, and then select Safe Mode with Networking from the list.

Run Windows 7 or Windows XP in Safe Mode with Networking

Video showing how to start Windows 7 in "Safe Mode with Networking":

Windows 8 users: Start Windows 8 is Safe Mode with Networking - Go to Windows 8 Start Screen, type Advanced, in the search results select Settings. Click Advanced startup options, in the opened "General PC Settings" window, select Advanced startup.

Click the "Restart now" button. Your computer will now restart into the "Advanced Startup options menu". Click the "Troubleshoot" button, and then click the "Advanced options" button. In the advanced option screen, click "Startup settings".

Click the "Restart" button. Your PC will restart into the Startup Settings screen. Press F5 to boot in Safe Mode with Networking.

Run Windows 8 in Safe Mode with Networking

Video showing how to start Windows 8 in "Safe Mode with Networking":

Windows 10 users: Click the Windows logo and select the Power icon. In the opened menu click "Restart" while holding "Shift" button on your keyboard. In the "choose an option" window click on the "Troubleshoot", next select "Advanced options".

In the advanced options menu select "Startup Settings" and click on the "Restart" button. In the following window you should click the "F5" button on your keyboard. This will restart your operating system in safe mode with networking.

Run Windows 10 in Safe Mode with Networking

Video showing how to start Windows 10 in "Safe Mode with Networking":

manual malware removal step 3Extract the downloaded archive and run the Autoruns.exe file.

Extract Autoruns.zip archive and run Autoruns.exe application

manual malware removal step 4In the Autoruns application, click "Options" at the top and uncheck "Hide Empty Locations" and "Hide Windows Entries" options. After this procedure, click the "Refresh" icon.

Refresh Autoruns application results

manual malware removal step 5Check the list provided by the Autoruns application and locate the malware file that you want to eliminate.

You should write down its full path and name. Note that some malware hides process names under legitimate Windows process names. At this stage, it is very important to avoid removing system files. After you locate the suspicious program you wish to remove, right click your mouse over its name and choose "Delete".

Delete malware in Autoruns

After removing the malware through the Autoruns application (this ensures that the malware will not run automatically on the next system startup), you should search for the malware name on your computer. Be sure to enable hidden files and folders before proceeding. If you find the filename of the malware, be sure to remove it.

Search for malware and delete it

Reboot your computer in normal mode. Following these steps should remove any malware from your computer. Note that manual threat removal requires advanced computer skills. If you do not have these skills, leave malware removal to antivirus and anti-malware programs.

These steps might not work with advanced malware infections. As always it is best to prevent infection than try to remove malware later. To keep your computer safe, install the latest operating system updates and use antivirus software. To be sure your computer is free of malware infections, we recommend scanning it with Combo Cleaner Antivirus for Windows.

Frequently Asked Questions (FAQ)

My computer is infected with msaRAT malware, should I format my storage device to get rid of it?

Formatting your storage device will remove msaRAT, but it will also delete every file on the drive. Running a trusted security program such as Combo Cleaner is the better first step, since it can eliminate the infection without wiping your data.

What are the biggest issues that msaRAT malware can cause?

msaRAT gives attackers remote control over the infected machine, allowing them to capture screenshots, run commands, and steal files. Since it operates within the Chaos ransomware ecosystem, an infection can also serve as a precursor to ransomware deployment, putting all stored data at risk.

What is the purpose of msaRAT malware?

msaRAT is designed to give the Chaos ransomware group covert remote access to infected computers. Operators can execute commands, capture screenshots, and exfiltrate files, and the persistent connection can be used to deliver further payloads at any time.

How did msaRAT malware infiltrate my computer?

msaRAT has been observed spreading as a fake Windows update - an MSI installer file pushed via a curl command. The Chaos group also uses spam emails and voice phishing to gain initial access. More broadly, threats of this kind reach victims through phishing emails, fake download sites, and pirated software.

Will Combo Cleaner protect me from malware?

Yes. Combo Cleaner can detect and remove most known malware, including Remote Access Trojans. Because sophisticated threats can embed themselves deeply in a system, running a full scan is the best way to ensure the infection is fully cleared.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate