← Back to Feed

Not Every Fox is Silver: Inside an AtlasRAT loader chain

July 27, 2026 · AhnLab ASEC · Severity: HIGH

This report analyzes a four-stage in-memory loader chain delivering AtlasRAT, starting with a Delphi executable disguised as AGE Flash Player. The final payload uses TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes.

Key Takeaways

  • Delphi executable disguised as AGE Flash Player initiates four-stage loader chain.
  • Final payload uses TLS-based ChaCha20 encryption for C2 communication.
  • AtlasRAT performs offline keylogging and DLL injection into WeChat processes.
☕ Buy a Coffee