APT hacking group AtlasCross targets organizations

A new advanced persistent threat (APT) hacking group named AtlasCross has been discovered targeting organizations with phishing lures impersonating the American Red Cross to deliver backdoor malware.

Cybersecurity firm NSFocus identified two previously undocumented trojans, DangerAds and AtlasAgent, associated with attacks by the new APT group.

NSFocus reports that the AtlasCross hackers are sophisticated and evasive, preventing the researchers from determining their origin.

The group’s attacks begin with a phishing email that pretends to be from the American Red Cross, requesting the recipient to participate in a “September 2023 Blood Drive.” The email contains a macro-enabled Word document (.docm) attachment that urges the victim to click “Enable Content” to view the hidden content. Doing so will trigger malicious macros that infect the Windows device with the DangerAds and AtlasAgent malware.

DangerAds functions as a loader, assessing the host environment and running built-in shellcode if specific strings are found in the system’s username or domain name. This suggests that AtlasCross has a narrow targeting scope, focusing on specific organizations or industries. Eventually, DangerAds loads x64.dll, which is the AtlasAgent trojan, the final payload delivered in the attack.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

May 31, 2025 A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21 more...

May 31, 2025 A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny more...

May 31, 2025 (EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked — more...

April 22, 2025 Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.