← Back to Feed
Not Every Fox is Silver: Inside an AtlasRAT loader chain
July 27, 2026 · AhnLab ASEC · Severity: HIGH
This report analyzes a four-stage in-memory loader chain delivering AtlasRAT, starting with a Delphi executable disguised as AGE Flash Player. The final payload uses TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes.
Key Takeaways
- Delphi executable disguised as AGE Flash Player initiates four-stage loader chain.
- Final payload uses TLS-based ChaCha20 encryption for C2 communication.
- AtlasRAT performs offline keylogging and DLL injection into WeChat processes.