Not Every Fox is Silver: Inside an AtlasRAT loader chain
ID: ff138abd-176e-573c-8d3e-b25d9e0ddc16
STIX ID: report--ff138abd-176e-573c-8d3e-b25d9e0ddc16
Feed Name: ASEC
AtlasRAT is a Windows-based modular remote access trojan delivered via a four-stage in-memory loader that begins with a Delphi executable disguised as Flash Player; the final payload supports TLS-based ChaCha20-encrypted C2, plugin execution, offline keylogging, DLL injection (targeting WeChat), and persistence via BITS and NTUSER.MAN. Analysis of VirusTotal samples indicates a builder-style production with multiple builds and diverse infrastructure; the report provides file and network IOCs, certificate markers, MITRE ATT&CK mappings, and threat-hunting rules but stops short of firm actor attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
