Discover the latest articles and insights on Dark Atlas
September 08, 2026
23 min read
Executive summary Hagaseca is an Android malware cluster associated with exposed Android Debug Bridge (ADB) services. This analysis examines the Hagaseca Android RAT loader known as THost9. RAT stands for remote access trojan. A RAT can let an attacker control an infected device remotely. The loader hides executable code inside an Android application package (APK). ...
September 01, 2026
28 min read
DragonForce is more than a ransomware name. It is a ransomware service ecosystem that affiliates can use to deploy different lockers and intrusion tools. This analysis focuses on one verified DragonForce Windows locker. The sample is a 32-bit Windows executable. It can encrypt local files, encrypt accessible SMB shares, remove shadow copies, stop selected processes, ...
June 24, 2026
38 min read
Executive Summary LoaderClient is a Minecraft-based malware loader linked to the WeedHack Malware-as-a-Service campaign. It is distributed as a malicious Minecraft Fabric mod and is designed to steal Minecraft session data, including display name, account UUID, and live Microsoft OAuth access tokens. What makes LoaderClient especially notable is its command and control architecture. Instead of ...
June 09, 2026
32 min read
Overview The enterprise threat landscape in 2026 has been reshaped by the rapid ascent of “The Gentlemen” — a Ransomware-as-a-Service (RaaS) operation tracked by Microsoft Threat Intelligence as Storm-2697 and by other security research firms under the alias LARVA-368. Since its emergence in mid-2025, this financially motivated syndicate has scaled faster than any other ransomware group on record, ...
May 25, 2026
15 min read
Payload ransomware is a Windows ransomware family that appends the .payload extension to encrypted files, drops RECOVER_payload.txt ransom notes, and uses ChaCha20 encryption with per-file Curve25519 ECDH key exchange. The sample also includes anti-forensics features such as ETW patching, VSS deletion, Windows Event Log clearing, and process/service termination. Key Takeaways Overview On 15 February 2026, ...
May 18, 2026
13 min read
PlugX (KorPlug) is a modular remote access trojan delivered in this campaign through an MSI-based DLL sideloading chain. In this sample,The installer drops a legitimate G DATA executable, a malicious AVK.dll sideloader, and an XOR-encrypted AVKTray.dat payload that ultimately loads a reflective PlugX DLL and establishes persistence. Key Takeaways Introduction A PlugX DLL sideloading campaign ...
May 13, 2026
17 min read
Phantom Stealer is a two-layer Windows infostealer attack chain that uses a malicious pdh.dll loader, process hollowing into jsc.exe, aggressive anti-analysis checks, browser and wallet theft, and a cryptocurrency clipper to steal credentials, financial data, and crypto-related assets while maintaining stealth and persistence. Key Takeaways Introduction A threat actor recently deployed Phantom Stealer, a carefully ...
May 06, 2026
10 min read
Executive Overview Salat Stealer is a sophisticated Go-based Remote Access Trojan (RAT) with deep information-stealing capabilities. Rather than acting as a simple stealer, it functions as a full post-exploitation framework with features that include WebSocket/QUIC command-and-control (C2), remote shell access, desktop and webcam streaming, browser and crypto-wallet theft, keylogging, clipboard theft, and SOCKS5 pivoting. The ...
April 27, 2026
21 min read
Overview On January 19, 2026, the Vect ransomware operation publicly announced its affiliate program through a post on a Brechforums, marking a clear step toward scaling its ransomware-as-a-service (RaaS) model. The announcement was made by the actor behind the operation (“vect”), who used the platform to introduce the program and share access to a dedicated ...