A new campaign has been discovered that spreads a remote access Trojan (RAT) called AtlasRAT via a fake Flash Player installer. This scam capitalizes on the continued search for Flash completions since Adobe ended support for Flash Player in 2020. The initial infection occurs through a Delphi executable named 'FlashPlay.Exe,' disguised as an 'AGE Flash Player' installer. AtlasRAT employs fileless malware techniques to avoid detection.
Once installed, it enables remote control of the infected system, allowing attackers to collect credentials, gather system information, exfiltrate data, and inject malicious code into other applications. To protect against such threats, users are advised to critically assess software installations, use up-to-date anti-malware solutions, and keep their systems updated.