# AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)

> AhnLab ASEC documented AtlasRAT, a modular remote access trojan delivered through a four-stage, largely in-memory loader chain that begins with a Delphi executable disguised as "AGE Flash Player." The final payload uses ChaCha20-over-TLS C2 communication with a spoofed Microsoft certificate, injects into WeChat, performs offline keylogging, and enumerates 33 security products; ASEC tracked 43 active AtlasRAT C2 servers as of 2026-06-09 and found partial marker overlap ("By@V<") with the Silver Fox threat actor's related "Atlas RAT"/AtlasCross campaigns, though the two variants use different handshake strings (BFuck vs. SFuck).

- **Published:** 2026-07-15T00:00:00Z
- **Last reviewed:** 2026-07-30T05:00:53.135Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1344
- **ID:** TL-2026-1344
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Void Arachne (China)
- **Detections:** 9 · **IOCs:** 61 (full data via the Threadlinqs MCP server — Purple tier)

## Description

AtlasRAT is a commercial-grade remote access trojan tracked by AhnLab ASEC in a report titled "Not Every Fox is Silver: Inside an AtlasRAT Loader Chain" (2026-07-15). The infection begins with a Delphi-compiled executable masquerading as an "AGE Flash Player" installer (Stage 1). This dropper decrypts and loads an embedded PE image (Stage 2) entirely in memory, which in turn reconstructs downloader shellcode from eight separately encrypted fragments (Stage 3). The shellcode reflectively maps and executes MainDll.dll, a 32-bit RAT payload, via a technique ASEC labels ServiceRun (Stage 4). No stage other than the initial dropper is written to disk, minimizing forensic artifacts and defeating static AV scanning of intermediate stages.

Once resident, AtlasRAT establishes command-and-control over TLS to 150.158.50.175:443, opening every session with an 8-byte handshake marker "BFuck\0\0\0" (hex 42 46 75 63 6b 00 00 00). The TLS session itself is wrapped in an additional application-layer ChaCha20 stream cipher, and the certificate presented is self-signed but spoofs the subject "CN=update.microsoft.com, O=Microsoft Corporation, C=US" (SHA-256 fingerprint 3f152103ea35c0f7feb205651a91e3c946b8057d1ea6f046ffc44fa611fd0267) to blend into HTTPS traffic logs and evade naive certificate-pinning defenses. ASEC's telemetry identified 43 active AtlasRAT C2 servers as of 2026-06-09, indicating an operationally mature, multi-tenant or affiliate-style infrastructure footprint consistent with a commercially distributed RAT rather than a single-operator tool.

The final-stage payload is built around a modular plugin architecture. Observed capabilities include offline/buffered keylogging (keystrokes cached locally and exfiltrated in batches rather than streamed live, reducing detectable network chatter), DLL injection into WeChat.exe to intercept or manipulate the popular Chinese messaging client, and a security-product inventory routine that fingerprints the presence of 33 distinct security executables on the host — behavior consistent with pre-attack reconnaissance intended to select an evasion profile or abort execution on well-defended hosts. General process/file enumeration and system information collection round out the plugin set. Persistence markers and configuration state are dropped to C:\Users\Public\Documents\ using the filenames offline.ini, MODIf.html, AtlasPro.ini, and Wxfun.dll, giving defenders concrete host-based indicators even though the loader chain itself is fileless.

ASEC's analysis explicitly compares AtlasRAT to previously reported "Silver Fox" activity. Silver Fox (also tracked as Void Arachne, SwimSnake, UTG-Q-1000, and "The Great Thief of Valley") is a Chinese-origin threat actor with a multi-year lineage running from Gh0st RAT derivatives through ValleyRAT, Gh0stCringe, HoldingHands RAT, and Winos 4.0 to the current "Atlas RAT" / AtlasCross family. Independent reporting (Hexastrike, The Hacker News, March 2026) documents a related Silver Fox campaign delivering an "Atlas RAT" via a triple-nested Setup Factory installer trojanizing a stolen Autodesk binary, dynamically resolving APIs via PEB walking, decrypting an embedded Gh0st RAT configuration, and downloading second-stage shellcode over raw TCP (port 9899) to a C2 domain bifa668[.]com (registered 2025-10-27, resolving to 61.111.250.139, ASN 138195 MOACK.Co.LTD, South Korea) fronted by nameservers a.share-dns.com/b.share-dns.net. That campaign's handshake, "SFuck\0\0\0" (hex 53 46 75 63 6b 00 00 00), differs from AtlasRAT's "BFuck" marker but the two samples share the distinct "By@V<" internal marker string, and both ultimately reflectively load a RAT DLL named/labeled as part of an "Atlas" family — the basis for ASEC's assessment of partial overlap without full identity. The related Silver Fox campaign used eleven brand-impersonating delivery domains (Zoom, Signal, Telegram, Surfshark VPN, Microsoft Teams, QuickQ VPN, UltraViewer, Trezor, KeFuBao, WangWang, plus one unattributed) registered in a single wave on 2025-10-27, code-signed installers abusing a stolen Extended Validation certificate issued to a Vietnamese entity (DUC FABULOUS CO., LTD, Hanoi), and native CLR-hosted PowerShell execution that disables AMSI, ETW, Constrained Language Mode, and ScriptBlock logging without ever spawning powershell.exe. Both the AtlasRAT and the related Silver Fox Atlas RAT lineage specifically target Chinese-speaking users and enumerate/disable Chinese security products (360 Total Security/360 Safe, Huorong, Kingsoft, QQ PC Manager), and both inject into or monitor WeChat.

This skeleton is scoped strictly to the ASEC-documented AtlasRAT sample and its 43-server C2 tracking; the related Silver Fox/AtlasCross infrastructure (bifa668[.]com, the eleven typosquat domains, and the stolen Autodesk/Setup Factory delivery chain) is documented here as corroborating attribution/overlap context, sourced independently from Hexastrike and The Hacker News reporting on the broader Silver Fox campaign active November 2025–March 2026.

## MITRE ATT&CK

- T1566 Phishing
- T1195 Supply Chain Compromise
- T1195.002 Compromise Software Supply Chain
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1204.002 User Execution: Malicious File
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1620 Reflective Code Loading
- T1055.001 Process Injection: Dynamic-link Library Injection
- T1685 Disable or Modify Tools
- T1685.001 Disable or Modify Windows Event Log
- T1553.006 Code Signing Policy Modification
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1056.001 Input Capture: Keylogging
- T1518.001 Security Software Discovery
- T1082 System Information Discovery
- T1057 Process Discovery
- T1083 File and Directory Discovery
- T1021.001 Remote Services: Remote Desktop Protocol
- T1056 Input Capture
- T1074.001 Data Staged: Local Data Staging
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1071.001 Application Layer Protocol: Web Protocols
- T1008 Fallback Channels
- T1095 Non-Application Layer Protocol
- T1583.001 Acquire Infrastructure: Domains
- T1588.003 Obtain Capabilities: Code Signing Certificates
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1587.001 Develop Capabilities: Malware
- T1566.002 Phishing: Spearphishing Link
- T1106 Native API
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1197 BITS Jobs
- T1543.003 Create or Modify System Process: Windows Service
- T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
- T1036.005 Match Legitimate Resource Name or Location
- T1036.001 Masquerading: Invalid Code Signature
- T1553.002 Code Signing
- T1070.004 Indicator Removal: File Deletion

## Sources

- [Not Every Fox is Silver: Inside an AtlasRAT Loader Chain](https://asec.ahnlab.com/ko/94478/)
- [Trust the Tunnel, Get the Trojan: Silver Fox Delivers Atlas RAT via Weaponized VPN Installers](https://hexastrike.com/resources/blog/threat-intelligence/trust-the-tunnel-get-the-trojan-silver-fox-delivers-atlas-rat-via-weaponized-vpn-installers/)
- [Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains](https://thehackernews.com/2026/03/silver-fox-expands-asia-cyber-campaign.html)
- [Analyzing the Silver Fox tax campaign and the new ABCDoor backdoor](https://securelist.com/silver-fox-tax-notification-campaign/119575/)
- [TA4922: The Suspected Chinese Crime Group is Going Global](https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global)
- [New Silver Fox Attack Pushes Malware Through Software Update Lures](https://cyberpress.org/silver-fox-update-lures/)
- [Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia](https://thehackernews.com/2026/05/silver-fox-deploys-abcdoor-malware-via.html)
- [Silver Fox group uses new Rust-based MODBEACON RAT](https://www.scworld.com/brief/silver-fox-group-uses-new-rust-based-modbeacon-rat)
- [SilverFox ValleyRAT Campaign Uses Eight-Stage Chain to Deploy Kernel Rootkit](https://cyberpress.org/silverfox-deploys-kernel-rootkit/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1344
