Atlas RAT is a Windows modular remote access trojan and backdoor associated with Chinese-speaking threat activity, including campaigns linked to TA4922 and broader overlap with the Silver Fox/Void Arachne ecosystem. It has been used in financially motivated intrusion campaigns as well as software-impersonation malware distribution operations, with targeting observed across East Asia and later expanding into Europe and Africa. Delivery has included phishing lures themed around human resources, payroll, invoicing, tax, and business communications, as well as trojanized software installers delivered from counterfeit download sites. Atlas RAT has also been deployed through DLL sideloading and reflective in-memory loading chains.
The malware is a multi-stage implant in which a loader or shellcode stage retrieves and maps the Atlas RAT DLL directly into memory, followed by download of a core module and optional auxiliary plugins. Atlas RAT supports broad remote administration and post-compromise activity, including system reconnaissance, arbitrary command execution, file operations, targeted file theft, plugin and payload download, screenshot capture, keylogging, clipboard capture, audio recording, webcam capture, remote session management, screen and input control, and system shutdown or reboot. Reported variants also support process injection and execution of additional code or modules on demand.
Atlas RAT incorporates multiple defense-evasion and anti-analysis features. Observed samples perform sandbox and virtualization checks before enabling capabilities, and some variants use direct syscalls and reflective loading to reduce visibility. In one extensively analyzed campaign, Atlas RAT embedded the PowerChell framework to host the .NET CLR inside the malware process and execute PowerShell without launching the standard interpreter, while disabling AMSI, ETW PowerShell tracing, Constrained Language Mode, and ScriptBlock logging. Communications have been described as encrypted, including ChaCha20-protected command-and-control traffic in some variants, with fallback networking support also observed.
Persistence and operator resilience features have been documented. Atlas RAT has established persistence through scheduled tasks, supported self-deletion routines, and in some campaigns was bundled with tooling to hijack remote desktop sessions. Additional behavior observed in the software-impersonation cluster included interference with Chinese security products by terminating their active network connections and the ability to inject into communication software for follow-on abuse.
Atlas RAT is best characterized as a full-featured modular RAT/backdoor used for sustained remote access, surveillance, theft, and follow-on payload delivery on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A reflective PE loader within the shellcode maps the Atlas RAT DLL into memory and invokes it directly.
A reflective PE loader within the shellcode maps the Atlas RAT DLL into memory and invokes it directly.
A reflective PE loader within the shellcode maps the Atlas RAT DLL into memory and invokes it directly.
Recent campaigns delivered a newly identified backdoor, Atlas RAT, alongside two fresh loader families Proofpoint named RomulusLoader and SilentRunLoader...
35 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker relied primarily on human resources and business-themed lures to target victims. These campaigns delivered credential phishing, fraud, and a newly identified malware called Atlas RAT.
Persistence is established through the embedded PowerShell engine, which creates a scheduled task under MicrosoftWindowsAppID.
Atlas RAT is a fully featured backdoor with capabilities including keylogging, screen capture, webcam recording, file management, and remote command execution.
The RAT embeds the PowerChell framework, a native C/C++ PowerShell execution engine that hosts the .NET CLR directly within the malware process and disables AMSI, ETW, Constrained Language Mode, and ScriptBlock logging before executing any commands.
Persistence is established through the embedded PowerShell engine, which creates a scheduled task under MicrosoftWindowsAppID.
On receiving command 0x13 from the C2 server, it writes the operator-supplied payload to C:UsersPublicDocumentsWxfun.dll ... allocates RWX memory in the target via VirtualAllocEx, writes the DLL path, and triggers loading via CreateRemoteThread with LoadLibraryW as the entry point.
The trojanized loader resolves its APIs dynamically through PEB walking, decrypts an embedded Gh0st RAT configuration, and downloads a second-stage shellcode payload over raw TCP, all without writing the final payload to disk.
All identified installer packages carry the same stolen Extended Validation code-signing certificate issued to a Vietnamese shell entity, lending them an appearance of legitimacy that bypasses both user suspicion and automated trust checks.
On receiving command 0x13 from the C2 server, it writes the operator-supplied payload to C:UsersPublicDocumentsWxfun.dll ... allocates RWX memory in the target via VirtualAllocEx, writes the DLL path, and triggers loading via CreateRemoteThread with LoadLibraryW as the entry point.
ETW bypass ... sets it to zero, silently suppressing all PowerShell tracing events.
The self-deletion routine uses a priority manipulation technique... then resumes it to execute a ping delay followed by del against the 8.3 short path.
Victims download ZIP archives containing a triple-nested Setup Factory installer that drops a trojanized Autodesk binary alongside a legitimate decoy application.
The Setup Factory runtime itself includes several anti-analysis checks. It scans for Xen hypervisor signatures... String references to IDA suggest the runtime also checks for the presence of disassemblers at runtime.
@ echo off for /f "skip=1 tokens=3" %%s in ( 'query user %USERNAME%' ) do ( set SESSION_ID=%%s )
Early in the initialization sequence the RAT also issues a WMI query ( SELECT * FROM Win32_VideoController ) to enumerate GPU hardware, likely for VM detection and host fingerprinting
Atlas RAT is a fully featured backdoor with capabilities including keylogging, screen capture, webcam recording, file management, and remote command execution.
Even so, the surveillance features in its malware, including audio, webcam and keylogging capture, could be sold to or used by espionage actors.
Atlas RAT is a fully featured backdoor with capabilities including keylogging, screen capture, webcam recording, file management, and remote command execution.
For example, the tool can record surrounding audio, capture webcam feeds, log keystrokes, and steal clipboard data .
The C2 protocol uses ChaCha20 encryption... An HTTP fallback channel via WinINet with the user-agent Mozilla/4.0 (compatible) provides an alternative communication path for file downloads and C2 traffic.
With the config decrypted, the loader connects to bifa668.com on port 9899 over raw TCP... then receives exactly 386,380 bytes of second-stage shellcode into the RWX buffer.
TA4922 might use a remote access Trojan (RAT), like ValleyRAT or Atlas RAT, to access targeted systems, or legitimate remote monitoring and management (RMM) software, like AnyDesk. In the latter case, it'll use a loader called RomulusLoader to bring the RMM onto the host system.
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan described as part of Silver Fox's broader toolset; the article notes multiple samples and versioned builds were identified, but attribution to Silver Fox is only circumstantial.
A malware family listed as part of Silver Fox's expanding arsenal.
A modular remote access trojan/backdoor used for surveillance and control. It can collect system information, execute arbitrary commands, record audio, capture webcam feeds, log keystrokes, steal clipboard data, and perform sandbox and virtualization checks before activating.
A newly identified remote access trojan used in TA4922 campaigns alongside credential phishing and fraud activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.