AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat
2 Articles
2 Articles
AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat
AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected command-and-control, log keystrokes offline. If inject malicious DLLs into WeChat, effectively turning the chat client into a long‑lived surveillance and control foothold on compromised hosts. Once launched, this first stage decrypts and loads an encrypted second-stage PE without writing traditi…
Fake Flash Player Installer Uses Microsoft-Themed Certificate to Deploy AtlasRAT
AtlasRAT is being delivered through a fake Flash Player installer that looks harmless but can give attackers remote control of a Windows computer. The campaign abuses a familiar software name to lower a victim’s guard, then loads much of its malicious code directly into memory, where it is harder for traditional file-based checks to catch. The threat highlights how old software brands still help criminals trick users into running harmful files. …
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium
