← Back to Feed

Not Every Fox is Silver: Inside an AtlasRAT loader chain

July 27, 2026 · AhnLab ASEC · Severity: HIGH

AhnLab ASEC analyzes AtlasRAT, a Windows remote access malware delivered through a four-stage in-memory loader chain disguised as AGE Flash Player. The final payload uses encrypted C2 communication, executes modular plugins, and performs keylogging and DLL injection into WeChat.

Key Takeaways

  • AtlasRAT uses a four-stage in-memory loader chain starting with a Delphi executable.
  • The final payload communicates via TLS-based ChaCha20-encrypted C2 channels.
  • It performs offline keylogging and injects DLLs into WeChat processes for stealth.
☕ Buy a Coffee