SYMBOLCOMMON_NAMEaka. SYNONYMS
win.atlas_rat (Back to overview)

Atlas RAT

Actor(s): TA4922


According to Proofpoint, Atlas RAT is a modular backdoor used by the TA4922 actor, delivered in multiple stages with a core module and optional plugins. It can gather system information, enumerate and exfiltrate files, and perform surveillance such as audio/video capture, along with the ability to download and run additional payloads. The loader uses anti-analysis techniques and loads the core module through a shellcode-based process, with capabilities to inject into other processes as part of its operation. The overall toolset is aligned with a Chinese-speaking actor and is designed to be extended through modular plugins fetched from the C2.

References
2026-06-03ProofpointProofpoint Threat Research Team
TA4922: The Suspected Chinese Crime Group is Going Global
Atlas RAT RomulusLoader SilentRunLoader TA4922
2026-03-25Hexastrike CybersecurityMaurice Fielenbach
Trust the Tunnel, Get the Trojan: Silver Fox Delivers Atlas RAT via Weaponized VPN Installers
Atlas RAT

There is no Yara-Signature yet.