logo

Fake Flash Player installs AtlasRAT

ID: dcf59e02-5781-5658-9047-72c1d3f8e9e8

STIX ID: report--dcf59e02-5781-5658-9047-72c1d3f8e9e8

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-07-31

Date Updated: 2026-07-31

...
...

Researchers describe a campaign that distributes AtlasRAT using fake Flash Player (and previously fake VPN) installers; the first-stage Delphi loader operates filelessly in memory and reconstructs a final payload (MainDll.Dll) that uses a self-signed certificate spoofing update.microsoft.com to establish TLS-encrypted C2. AtlasRAT provides persistent remote access with credential collection (offline keylogging), system and security-product reconnaissance, encrypted data exfiltration, and DLL injection into applications such as WeChat; recommended mitigations include verifying installers, using up-to-date anti-malware, and keeping systems updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.