AtlasBridge Overlay RAT (provisional)

Malware family · 1 sample(s) · 2 indicator record(s) · 1 signing certificate(s)

About AtlasBridge Overlay RAT (provisional)

Android overlay banker/RAT delivered inside an SVLT-XOR-v2 “vault” dropper (outer package com.system.loader.va363d031, a LaunchRouterActivity bootstrap). The dropper ships a vault-config.json that names the encrypted asset, its base64 key and the child package/hash, and a PayloadCipher that XOR-decrypts the asset (SVLT magic, embedded salt, plaintext = ct XOR salt XOR key) to a child.apk (com.atlasbridge.app). The child authenticates its C2 channel with SPAKE2 over a conscrypt TLS stack pinned by a custom x509TrustManager, carries per-device permission_profiles for overlay/accessibility abuse, and requests overlay, location and phone-state permissions. C2 recovered by a full static unpack of the vault; indicators binary-verified. Family label provisional; a single sample so far, so it is hash-attributed rather than decoder-ized.

Indicators

IndicatorTypeSampleFirst seen
ktx123.net domain 43168978b5b8… 2026-10-08
ktxapp.com domain 43168978b5b8… 2026-10-08