
AtlasRAT Hides Command Traffic Behind TLS and ChaCha20 Encryption
AtlasRAT is a newly documented Windows remote access trojan (RAT) that uses a multi‑stage loader chain and strong encryption to hide its command‑and‑control (C2) traffic from defenders. It combines TLS with ChaCha20 encryption, modular plugins, and stealthy persistence techniques to maintain long‑term, hard‑to‑detect access on compromised systems. AtlasRAT infections begin with a Delphi executable named […]
The post AtlasRAT Hides Command Traffic Behind TLS and ChaCha20 Encryption appeared first on Cyber Security News.