AtlasRAT is a Windows remote access Trojan delivered through multi-stage, largely in-memory loader chains that have been observed masquerading as fake software installers, including counterfeit Flash Player and VPN installers. The infection flow begins with a Delphi executable disguised as legitimate software, reconstructs encrypted intermediate components, manually maps later stages into memory, and ultimately launches a modular DLL-based RAT payload. This execution model minimizes disk artifacts and supports defense evasion.
AtlasRAT provides long-term remote control of compromised Windows hosts and supports encrypted command-and-control communications using TLS, with reporting indicating ChaCha20-protected traffic and the use of a self-signed certificate made to resemble Microsoft-themed infrastructure. Documented capabilities include plugin execution, downloading and executing additional payloads, process inspection, system and security-product reconnaissance, offline keylogging, data exfiltration, and DLL injection into applications such as WeChat. A dedicated persistence component has been reported to tamper with Windows mechanisms for logon persistence and to attempt User Account Control bypass through registry hijacking and CMSTPLUA.
The malware appears to be modular and actively developed, with multiple build variants and both x86 and x64 branches reported. AtlasRAT has been discussed alongside tooling associated with Silver Fox, ValleyRat, and related activity clusters, but any attribution to a specific threat actor remains unconfirmed. Available reporting more strongly supports the assessment that AtlasRAT is a reusable malware framework or privately distributed tool rather than a one-off implant tied to a single operator. Observed targeting is consistent with Windows users reached through social-engineering lures rather than a narrowly defined vertical, although the malware's capabilities make it suitable for espionage, credential collection, and broader post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The victimology and the modus operandi are also similar to those described in attacks involving SilverFox and their tools such as ValleyRat or AtlasRat.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The analyzed chain consists of a Delphi executable that is disguised as AGE Flash Player and loads an encrypted Stage 2 PE file, which then reconstructs the downloader shellcode from eight encrypted fragments.
Useful checks include ... remote thread creation using LoadLibraryW against WeChat.
Injecting DLLs into applications like WeChat, potentially allowing the attacker to monitor or manipulate messaging, or to hide malware activity or connectivity. | The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a technique often referred to as fileless malware.
the AtlasRAT infection chain starts with a Delphi executable named FlashPlay.Exe, masquerading as an “AGE Flash Player” installer.
Injecting DLLs into applications like WeChat, potentially allowing the attacker to monitor or manipulate messaging, or to hide malware activity or connectivity. | The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a technique often referred to as fileless malware.
The final payload (MainDll.Dll) uses a self-signed certificate spoofing CN=update.Microsoft.Com to initialize Transport Layer Security (TLS) client communication and encrypts Command and Control (C2) traffic.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AtlasRAT is a remote access trojan delivered via fake software installers, including a fake Flash Player and previously a fake VPN installer. It provides long-term remote control of infected Windows systems, supports offline keylogging for credential collection, gathers system information and installed security products, exfiltrates data over encrypted TLS channels, and injects DLLs into applications such as WeChat. The malware uses in-memory staging and reconstructs payloads to reduce obvious disk artifacts.
Windows remote-access trojan delivered via a fake Flash Player installer. It uses a four-stage in-memory loader chain, communicates with operators over encrypted TLS/ChaCha20 channels, supports plugins, can capture keystrokes, download and execute files, check processes, inject code into WeChat, and establish persistence via BITS database tampering, NTUSER.MAN logon persistence, and UAC bypass techniques.
Windows remote-access trojan delivered via a fake Flash Player installer. It uses a four-stage in-memory loader chain, communicates with operators over TLS and ChaCha20-encrypted C2, supports plugins, can capture keystrokes, download and execute files, inspect processes, inject code into WeChat, and establish persistence via BITS database tampering, NTUSER.MAN logon persistence, and UAC bypass techniques.
Named as another Silver Fox-associated RAT/tool for comparison with the campaign’s victimology and tradecraft; no technical analysis is provided in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.