AtlasBridge Overlay RAT (provisional)
Malware family · 30 sample(s) · 60 indicator record(s) · 1 signing certificate(s) · Active 2026-10-04 → 2026-10-10 (experimental)
About AtlasBridge Overlay RAT (provisional)
Android overlay banker/RAT delivered inside an SVLT-XOR-v2 “vault” dropper (outer package com.system.loader.va363d031, a LaunchRouterActivity bootstrap). The dropper ships a vault-config.json that names the encrypted asset, its base64 key and the child package/hash, and a PayloadCipher that XOR-decrypts the asset (SVLT magic, embedded salt, plaintext = ct XOR salt XOR key) to a child.apk (com.atlasbridge.app). The child authenticates its C2 channel with SPAKE2 over a conscrypt TLS stack pinned by a custom x509TrustManager, carries per-device permission_profiles for overlay/accessibility abuse, and requests overlay, location and phone-state permissions. C2 recovered by a full static unpack of the vault; indicators binary-verified. Family label provisional; now tracked across 25 samples and decoded automatically by the ShellTemplateVault decoder (outer loader com.system.loader.va363d031, child com.atlasbridge.app).