← Back to Feed
Not Every Fox is Silver: Inside an AtlasRAT loader chain
July 27, 2026 · AhnLab ASEC · Severity: HIGH
AhnLab ASEC analyzes AtlasRAT, a Windows remote access malware delivered through a four-stage in-memory loader chain disguised as AGE Flash Player. The final payload uses encrypted C2 communication, executes modular plugins, and performs keylogging and DLL injection into WeChat.
Key Takeaways
- AtlasRAT uses a four-stage in-memory loader chain starting with a Delphi executable.
- The final payload communicates via TLS-based ChaCha20-encrypted C2 channels.
- It performs offline keylogging and injects DLLs into WeChat processes for stealth.