Threat reportMalwareTL-2026-1343
AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as AGE Flash Player
AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as (TL-2026-1343), also tracked as AtlasRAT (ASEC), is a high-severity malware campaign, first published 2026-07-14. It has no confirmed attribution, affects Microsoft Windows, maps to 16 MITRE ATT&CK techniques (T1027, T1036.005, T1055.001), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-1343
- Threat ID
- TL-2026-1343
- Also known as
- AtlasRAT (ASEC)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- unknown - not specified in source reporting
- Target regions
- China-adjacent / Chinese-speaking users (inferred from WeChat targeting)
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as
Malware and tooling: AtlasCross RAT, AtlasRAT, CN=update.Microsoft.Com, O=Microsoft Corporation, C=US
How AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as works
AhnLab ASEC identified AtlasRAT, a Delphi-compiled remote access trojan delivered through a four-stage, entirely in-memory loader chain disguised as an "AGE Flash Player" installer. The RAT uses ChaCha20-encrypted C2 traffic over TLS with a self-signed certificate spoofing Microsoft, performs offline keylogging, enumerates 33 security-product executables, and injects a DLL into WeChat. ASEC has tracked an active campaign with 43 distinct C2 servers since June 9, 2026.
AtlasRAT is delivered as a Delphi-compiled executable masquerading as an "AGE Flash Player" installer (Stage 1). Once executed, Stage 1 loads an encrypted PE file (Stage 2) that reconstructs downloader shellcode from eight separately encrypted fragments, keeping the malware off disk throughout. Stage 2 hands off to a downloader (Stage 3) that connects out to attacker infrastructure and retrieves the final 32-bit RAT payload, a DLL internally named MainDll.Dll (Stage 4), which is launched via a technique ASEC labels ServiceRun. The entire chain executes in memory with no stage persisted to disk as a standalone file, an evasion property that materially degrades static, disk-based AV/EDR detection.
Command-and-control traffic is encrypted with ChaCha20 and wrapped inside a standard TLS session, with the initial handshake carrying an 8-byte protocol marker of "BFuck\0\0\0" used to identify legitimate C2 responses. The malware's TLS endpoint presents a self-signed certificate whose subject is deliberately crafted to impersonate Microsoft (CN=update.Microsoft.Com, O=Microsoft Corporation, C=US), a social-engineering-for-machines technique intended to blend into TLS inspection logs and cursory certificate review. ASEC observed a primary C2 server at 150.158.50.175 on port 443, plus secondary infrastructure at 108.187.7.84, 116.204.169.70, 143.92.32.49, 143.92.32.65, and 143.92.32.72, and states the operators have rotated across 43 distinct C2 servers since the campaign was first tracked on June 9, 2026.
Once established, AtlasRAT persists a small set of support files under the world-writable C:\Users\Public\Documents path (offline.Ini, MODIf.Html, AtlasPro.Ini, and Wxfun.DLL), names chosen to blend in with benign configuration/cache artifacts. Its capability set includes offline keylogging (buffering keystrokes for later exfiltration rather than streaming them live, reducing network signal), enumeration of an inventory of 33 known security-product executables to fingerprint the defensive posture of the host (ASEC's report does not enumerate the specific 33 product names), and targeted DLL injection into the WeChat process using a LoadLibraryW-based remote-thread-creation technique — consistent with the Wxfun.DLL artifact ASEC recovered, suggesting the injected module is used to hook or monitor WeChat activity on the host, a common targeting choice in campaigns aimed at Chinese-speaking or China-adjacent users and organizations.
ASEC's writeup notes overlap with a related but distinct campaign publicly documented by Hexastrike Cybersecurity: a Silver-Fox-attributed 'AtlasCross RAT' delivered via weaponized VPN installers, which shares the AtlasPro.ini artifact name and a near-identical 8-byte handshake structure ("SFuck\0\0\0" vs. AtlasRAT's "BFuck\0\0\0") and ChaCha20-with-per-packet-random-key C2 design, but differs materially in delivery lure (weaponized VPN installer vs. fake Flash Player), certificate strategy (stolen EV certificate issued to a Vietnamese entity vs. a self-signed Microsoft-impersonating certificate), and C2 infrastructure. These are treated in this record as related-but-distinct tooling/campaigns within a broader Chinese-speaking-actor RAT ecosystem targeting WeChat users, not as the same malware family, per both ASEC's and Hexastrike's own disambiguation.
No CVE is associated with this threat — delivery is via social engineering (a trojanized fake installer) rather than exploitation of a specific vulnerability. Note: a second, unrelated malware family also publicly referred to as "Atlas RAT" was reported by Proofpoint in connection with the financially motivated group TA4922 targeting Europe and East Asia — that family's TTPs (HR-themed phishing, GoFile-hosted ZIPs, DLL sideloading, audio recording, anti-sandbox checks against Microsoft Defender Application Guard/CExecSvc/OS UUID) are distinct from both ASEC's AtlasRAT and Hexastrike's AtlasCross RAT and are NOT conflated in this record; no attribution link between TA4922's Atlas RAT and ASEC's AtlasRAT has been established from available sources.
MITRE ATT&CK techniques used in TL-2026-1343
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.001 Dynamic-link Library Injection; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading
Collection
Discovery
T1057 Process Discovery; T1518.001 Security Software Discovery
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography
Execution
T1106 Native API; T1204.002 Malicious File
Persistence
defense-impairment
Initial Access
Affected products and versions in AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as
- Microsoft — Windows
Vulnerable versions: all supported versions targeted via social engineering, not a version-specific vulnerability
Remediation for AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as
Immediate actions
- Block C2 IPs 150.158.50.175, 108.187.7.84, 116.204.169.70, 143.92.32.49, 143.92.32.65, and 143.92.32.72 at perimeter firewall/proxy and add to TLS-inspection deny/alert lists
- Hunt for the file artifacts offline.Ini, MODIf.Html, AtlasPro.Ini, and Wxfun.DLL under C:\Users\Public\Documents on endpoints
- Hunt for the reported AtlasRAT sample hashes across endpoint/EDR telemetry
- Alert on TLS certificates presenting subject CN=update.Microsoft.Com, O=Microsoft Corporation, C=US that are self-signed rather than chained to a trusted Microsoft root
- Alert on process injection into WeChat.exe (remote thread creation via LoadLibraryW) via EDR
- Alert on the 8-byte TLS-session protocol markers "BFuck\0\0\0" (AtlasRAT) and the related "SFuck\0\0\0" (Silver Fox AtlasCross RAT) observed in outbound traffic
Workarounds
- Restrict execution of unsigned/self-published installers from user-writable download locations via application control (AppLocker/WDAC)
- Remove or block legacy Flash Player installer/update prompts entirely, since Adobe Flash Player reached end-of-life in December 2020 and no legitimate update should ever be offered
Longer-term hardening
- Deploy EDR with in-memory/fileless execution detection (reflective loading, shellcode staging from encrypted fragments)
- Deploy TLS certificate-pinning/anomaly detection to catch impersonated vendor certificate subjects
- User awareness training against trojanized "Flash Player"/plugin-update installers, which remain a recurring lure years after Flash's end-of-life
- Monitor writes to world-writable paths such as C:\Users\Public\Documents for executable/DLL/config artifacts
Timeline of AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as
- Hexastrike reports multiple delivery domains for the related Silver-Fox-attributed AtlasCross RAT campaign registered in batch provisioning, preceding observed deployment by weeks to months.
- Earliest identified AtlasCross RAT executables observed by Hexastrike (November 2025), marking the start of a four-month, high-tempo operational window spanning ~20 related RAT DLLs through March 2026.
- A dropped AtlasCross RAT configuration file analyzed by Hexastrike records an internal infection timestamp of 2026-03-09 20:58.
- Hexastrike Cybersecurity publishes analysis of a related but distinct Silver-Fox-attributed 'AtlasCross RAT' campaign sharing the AtlasPro.ini artifact and near-identical 8-byte handshake structure.
- Hexastrike analyzes the newest observed AtlasCross RAT payload sample, collected roughly one day prior to publication, confirming continuously updated delivery infrastructure through March 2026.
- AtlasRAT operators rotate across 43 distinct C2 servers during the tracked campaign window (2026-06-09 through report publication).
- ASEC begins tracking the AtlasRAT campaign; first of 43 identified C2 servers observed.
- Four-stage memory-only loader chain, ChaCha20/TLS C2 with spoofed Microsoft certificate, WeChat DLL injection, and 33-product security-software enumeration disclosed publicly for the first time.
- AhnLab ASEC publishes technical analysis 'AtlasRAT: A New Type of Malware Distributed via Memory-Only Multi-Stage Loader' (asec.ahnlab.com/en/94479/).
- Threat ingested into the Threadlinqs Intelligence pipeline for RESEARCH; overlap with Hexastrike's related AtlasCross RAT reporting identified and disambiguated.
Sources cited for AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as
- AtlasRAT: A New Type of Malware Distributed via Memory-Only Multi-Stage Loader
- Trust the Tunnel, Get the Trojan: Silver Fox Delivers Atlas RAT via Weaponized VPN Installers
- MITRE ATT&CK - T1620: Reflective Code Loading
- MITRE ATT&CK - T1573.001: Encrypted Channel - Symmetric Cryptography
- MITRE ATT&CK - T1518.001: Security Software Discovery
- Adobe Flash Player End of Life
Detection coverage for TL-2026-1343
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1343 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.