Fake Flash Installer Drops AtlasRAT

Malwarebytes · High sophistication
Last updated July 31, 2026

Researchers reported a real malware campaign where attackers trick people searching for Flash Player into installing a fake “Flash” installer that delivers the AtlasRAT remote-access trojan. Once installed, AtlasRAT gives the attacker long-term remote control, including credential theft and data exfiltration, while hiding activity using in-memory (“fileless”) techniques and encrypted command-and-control.

How the attack worked

This campaign relies on the fact that Adobe Flash Player is end of life, yet some users still search for it to run old games, sites, or business applications. Attackers built a fake installer branded as “AGE Flash Player” with the executable name FlashPlay.Exe, designed to look familiar and legitimate to anyone still hunting for a Flash download.

Once run, the installer kicks off an infection chain that leads to AtlasRAT, a remote access trojan. The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a fileless technique that helps the malware avoid detection by tools looking for suspicious files on the endpoint.

Why it succeeded

The lure works because it targets a real, persistent need. People still go looking for Flash Player because a surprising amount of content and software was built around Flash and never properly migrated. That ongoing demand gives attackers a believable pretext: an installer that promises to make old content work again.

The technical design compounds the problem. AtlasRAT uses a self-signed certificate spoofing CN=update.Microsoft.Com to encrypt its command-and-control traffic, making malicious network activity harder to distinguish from legitimate update traffic. Post-infection, it can perform offline keylogging, credential collection, system reconnaissance, encrypted data exfiltration, and DLL injection into applications like WeChat, giving attackers a wide range of capabilities once inside.

What to watch for

  • Installers for discontinued software like Flash Player, especially when found through general web search or sponsored results
  • Executable or branding names that don't match an official vendor, such as FlashPlay.Exe or “AGE Flash Player”
  • Prompts to install unfamiliar software to view content or fix an application
  • Unusual outbound network connections that appear to mimic update traffic but originate from unexpected processes

Building resistance

Organizations and individuals can reduce risk from this type of attack by treating any download of “popular search” software, particularly for discontinued products, as high risk and relying only on approved software sources. Employees should be encouraged to stop and verify with IT or security before installing anything prompted by a website or search result, since sponsored search placement is not a guarantee of legitimacy.

Because AtlasRAT and similar malware use fileless techniques and encrypted command-and-control traffic to hide activity, prevention at the point of download matters as much as endpoint detection. Security teams should also assume that once installed, this class of malware can collect credentials and exfiltrate data quietly, so monitoring for anomalous encrypted traffic and unexpected process behavior remains important even after the initial installer is blocked.

Key findings

  • Attackers leveraged continued demand for Flash by offering a fake Flash-related installer that looks legitimate.
  • The infection chain starts with a Delphi executable named `FlashPlay.Exe`, posing as an “AGE Flash Player” installer.
  • The first-stage loader runs in memory and reconstructs payloads instead of dropping obvious files (fileless technique).
  • AtlasRAT uses a self-signed certificate spoofing `CN=update.Microsoft.Com` to encrypt command-and-control traffic.
  • Post-infection capabilities include offline keylogging/credential collection, system reconnaissance, encrypted data exfiltration, and DLL injection into apps like WeChat.
  • Researchers suspect AtlasRAT may be a reusable/commercial framework rather than a single-group tool.

Who’s being targeted

  • Commonly targeted roles: All employees, IT/helpdesk, Security team, Procurement/software asset management.
  • Affected industries: Cross-industry (any Windows users installing unofficial software).
  • Attack channels: website.
  • Impersonated: “AGE Flash Player” (fake Flash installer branding).

Red flags to watch for

  • Flash Player is end-of-life and no longer supported, so new installers are suspicious
  • Unverified/unofficial download source (e.g., found via search results)
  • Installer name/branding doesn’t match an official Adobe source
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is AtlasRAT?

AtlasRAT is a remote access trojan delivered through a fake Flash Player installer that gives attackers long-term remote control of a victim's system, including credential theft and data exfiltration.

How does the fake Flash installer infect a system?

The infection chain starts with a Delphi executable named FlashPlay.Exe that poses as an AGE Flash Player installer, then runs a first-stage loader entirely in memory to reconstruct additional payloads without dropping obvious files to disk.

Why do people still fall for fake Flash Player downloads?

A surprising amount of content and business software was built around Flash and never migrated, so people still search for Flash installers, and attackers exploit that demand by wrapping malware in installers that look familiar and legitimate.

How does AtlasRAT hide its network traffic?

AtlasRAT uses a self-signed certificate spoofing CN=update.Microsoft.Com to initialize TLS communication, which encrypts its command-and-control traffic and helps it blend in with legitimate-looking connections.

Read the video transcript

Still hunting for Flash to run an old game or app? That search is exactly what AtlasRAT is waiting for. You click that result, download FlashPlay.Exe, branded as 'AGE Flash Player'. It looks like a normal installer, but it quietly loads AtlasRAT in memory, no obvious files, then phones home using a fake 'update.Microsoft.Com' certificate. From there, AtlasRAT can log keystrokes offline, steal credentials, scan your system, even inject into apps like WeChat, all while hiding as encrypted traffic. The one big tell? Flash is dead, any new Flash installer is trouble. If a site tells you to install Flash or any plugin to make something work, stop. Don’t run it, send a quick ticket or screenshot to IT and ask them to check it first.

Categories

Similar attacks

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026
Hotel Wi‑Fi Hijack Pushes Fake Updates & Phishing

Hotel Wi‑Fi Hijack Pushes Fake Updates & Phishing

Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled phishing pages. Victims were tricked into installing malware disguised as browser/operating system updates, and some pages redirected users into…

August 3, 2026
Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026
Hijacked Hotel Wi‑Fi Serves Fake Updates

Hijacked Hotel Wi‑Fi Serves Fake Updates

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get…

August 1, 2026