Fake Flash Player installs AtlasRAT
ID: dcf59e02-5781-5658-9047-72c1d3f8e9e8
STIX ID: report--dcf59e02-5781-5658-9047-72c1d3f8e9e8
Feed Name: Malwarebytes Blog
Researchers describe a campaign that distributes AtlasRAT using fake Flash Player (and previously fake VPN) installers; the first-stage Delphi loader operates filelessly in memory and reconstructs a final payload (MainDll.Dll) that uses a self-signed certificate spoofing update.microsoft.com to establish TLS-encrypted C2. AtlasRAT provides persistent remote access with credential collection (offline keylogging), system and security-product reconnaissance, encrypted data exfiltration, and DLL injection into applications such as WeChat; recommended mitigations include verifying installers, using up-to-date anti-malware, and keeping systems updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
