
QR-PDF Phishing Hits M365, MFA Bypass Surges
Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…
Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate Chrome/Edge browser activity. The malware is delivered as a fake “Windows update” MSI and, once run, launches a browser in a special debug mode to tunnel attacker commands over encrypted WebRTC traffic via trusted cloud services.
Cisco Talos identified a remote access trojan, tracked as msaRAT, linked to the Chaos ransomware group. The infection chain starts with an MSI installer disguised as a routine Windows update. Once downloaded, often via a curl.exe command that pulls the file into ProgramData, the attacker executes it on the victim's machine. From there, the malware launches Chrome or Edge and controls the browser using the Chrome DevTools Protocol, allowing it to blend command-and-control traffic into ordinary browser activity.
The network side of this attack is what makes it notable. After an initial HTTPS negotiation, the malware communicates over encrypted WebRTC/DTLS traffic. To further obscure attacker infrastructure, the channel relies on trusted cloud services, including Cloudflare Workers for signaling, Google STUN, and a Twilio TURN relay. This means the traffic pattern looks close to legitimate cloud and video/voice service usage rather than a typical malware beacon.
The social engineering hook is simple: a fake Windows update. Employees are conditioned to install updates promptly, and an installer that looks like a routine patch is unlikely to raise suspicion on its own. Chaos is described as operating as ransomware-as-a-service, using both vishing calls and spam email for initial access, which gives the group two separate paths to convince a target to run the installer, either through a phone call from someone posing as IT support or through an email attachment.
Because the malicious traffic hides inside normal browser and cloud-service behavior, network-based detection alone struggles to catch it. Endpoint visibility into what actually launched the browser process becomes far more useful than watching the wire.
Organizations can reduce risk by reinforcing that legitimate Windows updates come through managed patch tooling, not standalone installers requested by phone or email. IT helpdesk staff and executive assistants, who are common social engineering targets, should be trained to verify any unsolicited update request through a separate, trusted channel before acting. Encouraging staff to report unusual device behavior after running any installer, such as unexpected browser activity, helps close the gap between infection and detection. Finally, security teams should remember that attackers increasingly hide inside trusted applications and cloud services, so endpoint monitoring of process launches deserves as much attention as network monitoring.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is delivered as an MSI installer impersonating a Windows update, often pulled down via a curl.exe command into ProgramData and then executed by the attacker.
Once running, it launches Chrome or Edge and controls the browser via the Chrome DevTools Protocol, tunneling commands over encrypted WebRTC traffic that looks like normal HTTPS negotiation.
Yes, the Chaos ransomware-as-a-service group is described as using both vishing calls and spam email for initial access before double extortion.
Any unusual browser behavior right after running an installer, such as Chrome or Edge starting with a remote debugging port, is a red flag worth reporting.
Delivery arrives dressed as a Windows update… but this one hides Chaos ransomware’s remote access tool. Cisco Talos saw Chaos-linked msaRAT shipped as an MSI impersonating a Windows update. Run it, and it quietly launches Chrome or Edge in debug mode, then tunnels commands over encrypted WebRTC using Cloudflare, Google STUN, and Twilio. The tell: an email or phone call from 'IT' pushing you to run a random MSI or a curl.exe command for a Windows update, and then your browser pops open or runs in the background for no reason. If anyone tells you to install a Windows update outside our normal update or ticketing tools, stop and report it to IT immediately, don’t run the MSI, don’t run the command.

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites…

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed…