logo

Not Every Fox is Silver: Inside an AtlasRAT loader chain

ID: ff138abd-176e-573c-8d3e-b25d9e0ddc16

STIX ID: report--ff138abd-176e-573c-8d3e-b25d9e0ddc16

Feed Name: ASEC

Threat Score
75/100

Date Published: 2026-07-27

Date Updated: 2026-07-30

Author: ATCP

...
...

AtlasRAT is a Windows-based modular remote access trojan delivered via a four-stage in-memory loader that begins with a Delphi executable disguised as Flash Player; the final payload supports TLS-based ChaCha20-encrypted C2, plugin execution, offline keylogging, DLL injection (targeting WeChat), and persistence via BITS and NTUSER.MAN. Analysis of VirusTotal samples indicates a builder-style production with multiple builds and diverse infrastructure; the report provides file and network IOCs, certificate markers, MITRE ATT&CK mappings, and threat-hunting rules but stops short of firm actor attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.