SYMBOLCOMMON_NAMEaka. SYNONYMS
win.atlas_rat (Back to overview)

Atlas RAT

Actor(s): TA4922

VTCollection    

According to Proofpoint, Atlas RAT is a modular backdoor used by the TA4922 actor, delivered in multiple stages with a core module and optional plugins. It can gather system information, enumerate and exfiltrate files, and perform surveillance such as audio/video capture, along with the ability to download and run additional payloads. The loader uses anti-analysis techniques and loads the core module through a shellcode-based process, with capabilities to inject into other processes as part of its operation. The overall toolset is aligned with a Chinese-speaking actor and is designed to be extended through modular plugins fetched from the C2.

References
2026-06-03 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team
TA4922: The Suspected Chinese Crime Group is Going Global
Atlas RAT RomulusLoader SilentRunLoader TA4922
2026-03-25 ⋅ Hexastrike Cybersecurity ⋅ Maurice Fielenbach
Trust the Tunnel, Get the Trojan: Silver Fox Delivers Atlas RAT via Weaponized VPN Installers
Atlas RAT
Yara Rules
[TLP:WHITE] win_atlas_rat_auto (20260917 | Detects win.atlas_rat.)
rule win_atlas_rat_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.atlas_rat."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atlas_rat"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488d0576400100 488b4c2430 483bc8 7405 e8???????? }
            // n = 5, score = 100
            //   488d0576400100       | movzx               ecx, word ptr [edx + eax*2]
            //   488b4c2430           | inc                 cx
            //   483bc8               | cmp                 ecx, dword ptr [ecx + eax*2]
            //   7405                 | je                  0x8a
            //   e8????????           |                     

        $sequence_1 = { 418d4380 663bc8 7356 0fb6c1 4c8d051aa50000 41f644400201 }
            // n = 6, score = 100
            //   418d4380             | je                  0x76
            //   663bc8               | dec                 eax
            //   7356                 | mov                 eax, ebp
            //   0fb6c1               | dec                 esp
            //   4c8d051aa50000       | lea                 eax, [0x148f9]
            //   41f644400201         | dec                 eax

        $sequence_2 = { 4c893c24 4903eb 4c8d3d06ed0100 660f1f440000 ffcb }
            // n = 5, score = 100
            //   4c893c24             | dec                 eax
            //   4903eb               | cmp                 eax, -1
            //   4c8d3d06ed0100       | je                  0x8b0
            //   660f1f440000         | dec                 esp
            //   ffcb                 | lea                 ecx, [ebp + 0xc]

        $sequence_3 = { 4883ec20 488d052fd90000 488bf9 488901 8bda 4883c108 }
            // n = 6, score = 100
            //   4883ec20             | lea                 ecx, [edx + ecx*8]
            //   488d052fd90000       | mov                 edx, 0xfa0
            //   488bf9               | xor                 ebx, ebx
            //   488901               | dec                 eax
            //   8bda                 | lea                 edx, [0x1697d]
            //   4883c108             | inc                 ebp

        $sequence_4 = { ff15???????? 8945d0 8b7dd8 f20f1045d0 f20f1145e0 4c8d056f0e0100 }
            // n = 6, score = 100
            //   ff15????????         |                     
            //   8945d0               | mov                 edx, 0x80000000
            //   8b7dd8               | inc                 ecx
            //   f20f1045d0           | cmove               eax, eax
            //   f20f1145e0           | inc                 ebp
            //   4c8d056f0e0100       | xor                 ecx, ecx

        $sequence_5 = { 488d05fb1c0000 498b0b 4889442450 488b85e0040000 4889442460 }
            // n = 5, score = 100
            //   488d05fb1c0000       | dec                 eax
            //   498b0b               | lea                 edx, [0xfc29]
            //   4889442450           | dec                 eax
            //   488b85e0040000       | cmp                 eax, -1
            //   4889442460           | je                  0x113

        $sequence_6 = { 488d8d800c0000 ff15???????? 488d55e0 488d8d800c0000 ff15???????? 488bd8 }
            // n = 6, score = 100
            //   488d8d800c0000       | lea                 eax, [0x1c1f9]
            //   ff15????????         |                     
            //   488d55e0             | ret                 
            //   488d8d800c0000       | dec                 eax
            //   ff15????????         |                     
            //   488bd8               | sub                 esp, 0x28

        $sequence_7 = { 488d55e0 488d8d800c0000 ff15???????? 488bd8 4883f8ff 746f 4c8d4d0c }
            // n = 7, score = 100
            //   488d55e0             | mov                 eax, dword ptr [ebx]
            //   488d8d800c0000       | cmp                 dword ptr [eax], 0
            //   ff15????????         |                     
            //   488bd8               | jne                 0x9d6
            //   4883f8ff             | dec                 eax
            //   746f                 | lea                 edx, [0x9a1a]
            //   4c8d4d0c             | dec                 eax

        $sequence_8 = { 4863c9 4c8d05bc1b0100 488bc1 83e13f 48c1e806 488d14c9 }
            // n = 6, score = 100
            //   4863c9               | lea                 edi, [esp + 0x250]
            //   4c8d05bc1b0100       | mov                 dword ptr [esp + 0x44], 0xff
            //   488bc1               | mov                 ecx, 0x1fe
            //   83e13f               | mov                 dword ptr [esp + 0x40], 0x100
            //   48c1e806             | xor                 eax, eax
            //   488d14c9             | dec                 eax

        $sequence_9 = { 4885c0 7403 f0ff00 488d4138 41b806000000 488d15c7200100 }
            // n = 6, score = 100
            //   4885c0               | dec                 eax
            //   7403                 | sub                 esp, 0x20
            //   f0ff00               | jmp                 0x238
            //   488d4138             | dec                 eax
            //   41b806000000         | lea                 eax, [0x16913]
            //   488d15c7200100       | dec                 ebx

    condition:
        7 of them and filesize < 323584
}
Download all Yara Rules