Fake Flash Installer Drops AtlasRAT

Malwarebytes · High sophistication
Last updated July 31, 2026

Researchers reported a real malware campaign where attackers trick people searching for Flash Player into installing a fake “Flash” installer that delivers the AtlasRAT remote-access trojan. Once installed, AtlasRAT gives the attacker long-term remote control, including credential theft and data exfiltration, while hiding activity using in-memory (“fileless”) techniques and encrypted command-and-control.

How the attack worked

This campaign relies on the fact that Adobe Flash Player is end of life, yet some users still search for it to run old games, sites, or business applications. Attackers built a fake installer branded as “AGE Flash Player” with the executable name FlashPlay.Exe, designed to look familiar and legitimate to anyone still hunting for a Flash download.

Once run, the installer kicks off an infection chain that leads to AtlasRAT, a remote access trojan. The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a fileless technique that helps the malware avoid detection by tools looking for suspicious files on the endpoint.

Why it succeeded

The lure works because it targets a real, persistent need. People still go looking for Flash Player because a surprising amount of content and software was built around Flash and never properly migrated. That ongoing demand gives attackers a believable pretext: an installer that promises to make old content work again.

The technical design compounds the problem. AtlasRAT uses a self-signed certificate spoofing CN=update.Microsoft.Com to encrypt its command-and-control traffic, making malicious network activity harder to distinguish from legitimate update traffic. Post-infection, it can perform offline keylogging, credential collection, system reconnaissance, encrypted data exfiltration, and DLL injection into applications like WeChat, giving attackers a wide range of capabilities once inside.

What to watch for

  • Installers for discontinued software like Flash Player, especially when found through general web search or sponsored results
  • Executable or branding names that don't match an official vendor, such as FlashPlay.Exe or “AGE Flash Player”
  • Prompts to install unfamiliar software to view content or fix an application
  • Unusual outbound network connections that appear to mimic update traffic but originate from unexpected processes

Building resistance

Organizations and individuals can reduce risk from this type of attack by treating any download of “popular search” software, particularly for discontinued products, as high risk and relying only on approved software sources. Employees should be encouraged to stop and verify with IT or security before installing anything prompted by a website or search result, since sponsored search placement is not a guarantee of legitimacy.

Because AtlasRAT and similar malware use fileless techniques and encrypted command-and-control traffic to hide activity, prevention at the point of download matters as much as endpoint detection. Security teams should also assume that once installed, this class of malware can collect credentials and exfiltrate data quietly, so monitoring for anomalous encrypted traffic and unexpected process behavior remains important even after the initial installer is blocked.

Key findings

  • Attackers leveraged continued demand for Flash by offering a fake Flash-related installer that looks legitimate.
  • The infection chain starts with a Delphi executable named `FlashPlay.Exe`, posing as an “AGE Flash Player” installer.
  • The first-stage loader runs in memory and reconstructs payloads instead of dropping obvious files (fileless technique).
  • AtlasRAT uses a self-signed certificate spoofing `CN=update.Microsoft.Com` to encrypt command-and-control traffic.
  • Post-infection capabilities include offline keylogging/credential collection, system reconnaissance, encrypted data exfiltration, and DLL injection into apps like WeChat.
  • Researchers suspect AtlasRAT may be a reusable/commercial framework rather than a single-group tool.

Who’s being targeted

  • Commonly targeted roles: All employees, IT/helpdesk, Security team, Procurement/software asset management.
  • Affected industries: Cross-industry (any Windows users installing unofficial software).
  • Attack channels: website.
  • Impersonated: “AGE Flash Player” (fake Flash installer branding).

Red flags to watch for

  • Flash Player is end-of-life and no longer supported, so new installers are suspicious
  • Unverified/unofficial download source (e.g., found via search results)
  • Installer name/branding doesn’t match an official Adobe source
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is AtlasRAT?

AtlasRAT is a remote access trojan delivered through a fake Flash Player installer that gives attackers long-term remote control of a victim's system, including credential theft and data exfiltration.

How does the fake Flash installer infect a system?

The infection chain starts with a Delphi executable named FlashPlay.Exe that poses as an AGE Flash Player installer, then runs a first-stage loader entirely in memory to reconstruct additional payloads without dropping obvious files to disk.

Why do people still fall for fake Flash Player downloads?

A surprising amount of content and business software was built around Flash and never migrated, so people still search for Flash installers, and attackers exploit that demand by wrapping malware in installers that look familiar and legitimate.

How does AtlasRAT hide its network traffic?

AtlasRAT uses a self-signed certificate spoofing CN=update.Microsoft.Com to initialize TLS communication, which encrypts its command-and-control traffic and helps it blend in with legitimate-looking connections.

Read the video transcript

Still hunting for Flash to run an old game or app? That search is exactly what AtlasRAT is waiting for. You click that result, download FlashPlay.Exe, branded as 'AGE Flash Player'. It looks like a normal installer, but it quietly loads AtlasRAT in memory, no obvious files, then phones home using a fake 'update.Microsoft.Com' certificate. From there, AtlasRAT can log keystrokes offline, steal credentials, scan your system, even inject into apps like WeChat, all while hiding as encrypted traffic. The one big tell? Flash is dead, any new Flash installer is trouble. If a site tells you to install Flash or any plugin to make something work, stop. Don’t run it, send a quick ticket or screenshot to IT and ask them to check it first.

Similar attacks