NSFOCUS Security Labs recently discovered a new attack
process based on phishing documents in their daily threat-hunting operations.
Delving deeper into this finding through extensive research, they confirmed two
new Trojan horse programs and many rare attack techniques and tactics.
NSFOCUS Security Labs believes that this new attack process comes from a new
APT attacker, who has a high technical level and cautious attack
attitude. The phishing attack activity captured this time is part of
the attackeras targeted strike on specific targets and is its main means
to achieve in-domain penetration. NSFOCUS Security Labs validated the
high-level threat attributes of AtlasCross in terms of development technology
and attack strategy through an in-depth analysis of its attack metrics. At this
current stage, AtlasCross has a relatively limited scope of activity,
primarily focusing on targeted attacks against specific hosts within a network
domain. However, the attack processes they employ are highly
robust and mature. NSFOCUS Security Labs deduce that this attacker is
highly likely to deploy this attack process into larger-scale network attack
operations.
---------------------------------------------Updated July 31,
2026
(NSFOCUS) After an in-depth study of the attack
process, NSFOCUS Security Labs found that this APT attacker is quite
different from known attacker characteristics in terms of execution flow,
attack technology stack, attack tools, implementation details, attack
objectives, behavior tendency and other main attribution indicators. The
technical level and cautious attitude shown by this attacker during this
activity are also worthy of attention. Therefore, NSFOCUS Security
Labs identified the orchestrator of this event as a new attacker and named it
AtlasCross. NSFOCUS Security Labs validated the high-level threat attributes of
AtlasCross in terms of development technology and attack strategy through an
in-depth analysis of its attack metrics. The organizational
origin of the AtlasCross attacker cannot be determined.
First Seen in: 2023
Tools:
AtlasAgent (category:
Malware)
type: Reconnaissance, Backdoor, Downloader
(NSFOCUS) AtlasAgent programs made by AtlasCross support multiple
injection methods. AtlasAgent implements an injection method based
on kernel-layer functions, which can inject shellcode into existing or
new threads of other processes.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f24309a0-38d9-4d0a-bf4a-3f2815597c65
http://nsfocusglobal.com/warning-newly-discovered-apt-attacker-atlascross-exploits-red-cross-blood-drive-phishing-for-cyberattack/
https://malpedia.caad.fkie.fraunhofer.de/details/win.atlas_agent
DangerAds (category:
Malware)
type: Loader
(NSFOCUS) This is a loader Trojan used by AtlasCross in this activity. Its main
function is to detect the host environment and execute a built-in shellcode in
its own process, and then the shellcode loads and runs subsequent Trojan
programs.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=dacb52ee-802a-4f83-8a08-3021ed8e6447
http://nsfocusglobal.com/warning-newly-discovered-apt-attacker-atlascross-exploits-red-cross-blood-drive-phishing-for-cyberattack/
Source: https://andreacristaldi.github.io/APTmap/
