
GST-Themed Phishing Hits India With Remcos RAT
A real phishing campaign targeted Indian businesses and individual taxpayers by impersonating government departments and sending emails that look like official…
Researchers reported a real malware campaign where attackers trick people searching for Flash Player into installing a fake “Flash” installer that delivers the AtlasRAT remote-access trojan. Once installed, AtlasRAT gives the attacker long-term remote control, including credential theft and data exfiltration, while hiding activity using in-memory (“fileless”) techniques and encrypted command-and-control.
This campaign relies on the fact that Adobe Flash Player is end of life, yet some users still search for it to run old games, sites, or business applications. Attackers built a fake installer branded as “AGE Flash Player” with the executable name FlashPlay.Exe, designed to look familiar and legitimate to anyone still hunting for a Flash download.
Once run, the installer kicks off an infection chain that leads to AtlasRAT, a remote access trojan. The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a fileless technique that helps the malware avoid detection by tools looking for suspicious files on the endpoint.
The lure works because it targets a real, persistent need. People still go looking for Flash Player because a surprising amount of content and software was built around Flash and never properly migrated. That ongoing demand gives attackers a believable pretext: an installer that promises to make old content work again.
The technical design compounds the problem. AtlasRAT uses a self-signed certificate spoofing CN=update.Microsoft.Com to encrypt its command-and-control traffic, making malicious network activity harder to distinguish from legitimate update traffic. Post-infection, it can perform offline keylogging, credential collection, system reconnaissance, encrypted data exfiltration, and DLL injection into applications like WeChat, giving attackers a wide range of capabilities once inside.
Organizations and individuals can reduce risk from this type of attack by treating any download of “popular search” software, particularly for discontinued products, as high risk and relying only on approved software sources. Employees should be encouraged to stop and verify with IT or security before installing anything prompted by a website or search result, since sponsored search placement is not a guarantee of legitimacy.
Because AtlasRAT and similar malware use fileless techniques and encrypted command-and-control traffic to hide activity, prevention at the point of download matters as much as endpoint detection. Security teams should also assume that once installed, this class of malware can collect credentials and exfiltrate data quietly, so monitoring for anomalous encrypted traffic and unexpected process behavior remains important even after the initial installer is blocked.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
AtlasRAT is a remote access trojan delivered through a fake Flash Player installer that gives attackers long-term remote control of a victim's system, including credential theft and data exfiltration.
The infection chain starts with a Delphi executable named FlashPlay.Exe that poses as an AGE Flash Player installer, then runs a first-stage loader entirely in memory to reconstruct additional payloads without dropping obvious files to disk.
A surprising amount of content and business software was built around Flash and never migrated, so people still search for Flash installers, and attackers exploit that demand by wrapping malware in installers that look familiar and legitimate.
AtlasRAT uses a self-signed certificate spoofing CN=update.Microsoft.Com to initialize TLS communication, which encrypts its command-and-control traffic and helps it blend in with legitimate-looking connections.
Still hunting for Flash to run an old game or app? That search is exactly what AtlasRAT is waiting for. You click that result, download FlashPlay.Exe, branded as 'AGE Flash Player'. It looks like a normal installer, but it quietly loads AtlasRAT in memory, no obvious files, then phones home using a fake 'update.Microsoft.Com' certificate. From there, AtlasRAT can log keystrokes offline, steal credentials, scan your system, even inject into apps like WeChat, all while hiding as encrypted traffic. The one big tell? Flash is dead, any new Flash installer is trouble. If a site tells you to install Flash or any plugin to make something work, stop. Don’t run it, send a quick ticket or screenshot to IT and ask them to check it first.

A real phishing campaign targeted Indian businesses and individual taxpayers by impersonating government departments and sending emails that look like official…

Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks.…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked…

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed…