← Back to Feed

Fake Flash Player installs AtlasRAT

July 31, 2026 · Malwarebytes · Severity: MEDIUM

Researchers at Malwarebytes have uncovered a campaign distributing the remote access Trojan (RAT) AtlasRAT through a fake Adobe Flash Player installer. Despite Adobe ending support for Flash Player on December 31, 2020, and blocking Flash content, users continue to search for Flash to access legacy content, making them vulnerable. Attackers exploit this by disguising AtlasRAT as a legitimate Flash installer, named FlashPlay.Exe, labeled as “AGE Flash Player.” The malware uses fileless techniques, running entirely in memory to reconstruct payloads without leaving obvious traces on disk. The final payload, MainDll.Dll, employs a self-signed certificate spoofing CN=update.Microsoft.com to establish encrypted Command and Control (C2) communication, bypassing trust checks. Once installed, AtlasRAT grants attackers long-term remote control over infected Windows systems, enabling credential theft via keylogging, system reconnaissance, data exfiltration, and DLL injection into applications like WeChat. Researchers suspect AtlasRAT is a reusable framework or commercial tool, not limited to a single group. This campaign highlights the risks of downloading software from untrusted sources, especially when searching for outdated or niche applications. To mitigate such threats, users should verify software legitimacy, avoid sponsored search results, and maintain updated anti-malware solutions. Malwarebytes detects AtlasRAT as Malware.AI.1710771908 and recommends keeping operating systems and security software current to prevent infections.

Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer.

People still go looking for “Flash player” because a surprising amount of content and software was built around Flash and never properly migrated. Users often just want a quick way to get those old sites, games, or business apps working again.

The underlying problem is that Adobe ended support for Flash Player on December 31, 2020, and actively blocks Flash content from running in the official player.

Attackers know some people will still search for Flash to run a game or a business app, so they wrap their malware in a fake Flash‑related installer that looks familiar and legitimate.

That’s likely why the AtlasRAT infection chain starts with a Delphi executable named FlashPlay.Exe, masquerading as an “AGE Flash Player” installer. The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a technique often referred to as fileless malware.

The final payload (MainDll.Dll) uses a self‑signed certificate spoofing CN=update.Microsoft.Com to initialize Transport Layer Security (TLS) client communication and encrypts Command and Control (C2) traffic.

A self‑signed certificate means the owner signs with their own key instead of a trusted certificate authority (CA). That means an attacker can create a certificate claiming to be update.microsoft.com or google.com, even though they don’t control those domains. A web browser would reject such a certificate with a warning. Custom malware, however, can simply ignore the operating system’s trust checks and use it to set up encrypted C2.

Once AtlasRAT is installed, the operator gains long‑term remote control of the infected Windows system with capabilities including:

  • Collecting credentials via offline keylogging
  • Gathering system information and identifying installed security products
  • Exfiltrating data over encrypted channels
  • Injecting DLLs into applications like WeChat, potentially allowing the attacker to monitor or manipulate messaging, or to hide malware activity or connectivity.

Based on historical data, the researchers suspect that AtlasRAT is a reusable framework or commercial offering rather than a one-off tool used by a single group.

How to stay safe

When looking for apps and software to perform a specific task, remember that cybercriminals often exploit popular searches in semi-targeted attacks. In previous campaigns, for example, AtlasRAT has also been distributed as a fake VPN installer.

Some tips to keep this RAT, and others, off your computer:

  • Carefully check what you’re about to install. Sponsored search results are not a guarantee that software is legitimate.
  • Use an up-to-date, real-time anti-malware solution to detect and block remote access Trojans. Malwarebytes detected AtlasRAT as Malware.AI.1710771908
  • Keep your operating system, browser, and security software up to date.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Key Takeaways

  • Fake Flash Player installer delivers AtlasRAT remote access Trojan.
  • Attackers exploit users needing Flash for old content or apps.
  • First-stage loader runs fileless malware in memory to avoid detection.
☕ Buy a Coffee