Atlas RAT is a modular Windows remote access trojan and backdoor associated with Chinese-speaking threat activity, including campaigns attributed to TA4922 and reporting overlap with the Silver Fox ecosystem. It has been used in financially motivated intrusion campaigns that expanded from East Asia into Europe and South Africa, with targeting that included organizations reached through localized human resources, payroll, tax, invoice, benefits, and other business-themed social engineering lures.
Atlas RAT is designed as a multi-stage implant. Observed deployments use DLL sideloading to install the malware, after which it retrieves a core module and auxiliary plugins from command-and-control infrastructure. The malware supports broad host reconnaissance and remote command execution, enabling operators to profile compromised systems and carry out post-compromise actions. Reported functionality includes targeted file theft, plugin and payload download, keylogging, screenshot capture, clipboard theft, audio recording, webcam capture, and host control actions such as shutdown or reboot.
The malware incorporates anti-analysis and anti-sandbox checks before enabling its full capability set, including checks associated with virtualization and Microsoft Defender Application Guard environments. Reporting also notes use of direct syscalls for shellcode loading and encrypted command-and-control communications. Atlas RAT has been deployed selectively against higher-value targets within broader phishing-led campaigns, indicating its role as a more capable follow-on access and surveillance tool within a larger intrusion toolkit.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This new development indicates Silver Fox is actively refining its tradecraft, expanding its arsenal with malware families like Atlas RAT, ABCDoor, RomulusLoader, and SilentRunLoader.
For high-value targets, the threat group deploys Atlas RAT, a full-featured modular backdoor trojan. This advanced payload can harvest broad system specifications and execute arbitrary commands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker relied primarily on human resources and business-themed lures to target victims. These campaigns delivered credential phishing, fraud, and a newly identified malware called Atlas RAT.
RomulusLoader starts one or more “workers”, which are effectively copies of its code that are injected into other processes (such as svchost.exe and dllhost.exe).
The target receives a legitimate executable file and a malicious DLL (the Atlas RAT loader) that is sideloaded into the executable’s process.
Before activating these features, the backdoor runs several complex environmental checks . It verifies whether the host environment belongs to an automated analysis sandbox . Specifically, it checks for built-in sandbox names like WDAGUtilityAccount or virtualization flags like mshome . If the environment appears unsafe, the malware instantly terminates its execution to evade signature generation .
This advanced payload can harvest broad system specifications and execute arbitrary commands .
Atlas RAT is a fully featured backdoor with capabilities including keylogging, screen capture, webcam recording, file management, and remote command execution.
The malware also checks for a camera as well as the audio (recording and output) devices on the endpoint and sends this data to the C2.
Before activating these features, the backdoor runs several complex environmental checks . It verifies whether the host environment belongs to an automated analysis sandbox . Specifically, it checks for built-in sandbox names like WDAGUtilityAccount or virtualization flags like mshome . If the environment appears unsafe, the malware instantly terminates its execution to evade signature generation .
Proofpoint’s report highlights Atlas RAT, a recently identified remote access trojan that offers attackers the following capabilities: ... Targeted file theft
For example, the tool can record surrounding audio, capture webcam feeds, log keystrokes, and steal clipboard data .
Atlas RAT is a fully featured backdoor with capabilities including keylogging, screen capture, webcam recording, file management, and remote command execution.
For example, the tool can record surrounding audio, capture webcam feeds, log keystrokes, and steal clipboard data .
Atlas RAT ... connected to a command-and-control server at 206.238.115.58 over port 886... Network defenders should flag traffic to unusual ports, particularly port 1234, used by RomulusLoader’s C2 infrastructure.
These campaigns delivered credential phishing, fraud, and a newly identified malware called Atlas RAT. New loader families, designated RomulusLoader and SilentRunLoader, were also introduced to stage additional tools.
TA4922 might use a remote access Trojan (RAT), like ValleyRAT or Atlas RAT, to access targeted systems, or legitimate remote monitoring and management (RMM) software, like AnyDesk. In the latter case, it'll use a loader called RomulusLoader to bring the RMM onto the host system.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family listed as part of Silver Fox's expanding arsenal.
A modular remote access trojan/backdoor used for surveillance and control. It can collect system information, execute arbitrary commands, record audio, capture webcam feeds, log keystrokes, steal clipboard data, and perform sandbox and virtualization checks before activating.
A newly identified remote access trojan used in TA4922 campaigns alongside credential phishing and fraud activity.
Atlas RAT is a fully featured backdoor with capabilities including keylogging, screen capture, webcam recording, file management, and remote command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.