AtlasRAT is a modular Windows RAT delivered through a four-stage in-memory loader chain beginning with a Delphi executable disguised as Flash Player. The final payload (MainDll.Dll) establishes encrypted C2 over TLS using ChaCha20, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes. A separate persistence module (persistence86.Dll) provides BITS tampering, NTUSER.MAN-based logon persistence, and UAC bypass via CMSTPLUA and registry hijacking. The scale of 146 unique samples with multiple PDB builds suggests commercial or private distribution rather than a single operator.
silverfox
1 post
Not Every Fox is Silver: Inside an AtlasRAT loader chain