Chinese hackers use new Atlas RAT malware in European cyberattacks
2026-06-04T01:23:31Z•63c47bbc89ff2d856f2e6d383e2d0d9d890686610ef7ea8861c862f3602bfa84
ATGCISAFBINSAOFACacer-wave-7androidatlas-ratchinese-actorscve-2026-8206denial-of-servicefuel-tank-monitoringgithub-token-thefthttp2-bombindustrial-control-systemskirkilinux-kernelminecraft-malware','ai-ransomware-toolkit','edr-evasion'nobitexransomwareratvs-code-zero-dayweedhackwordpresszero-day
What happened
Multiple high-risk cyber events reported: a Chinese-speaking group is deploying a new Atlas RAT and previously undocumented malware in European intrusions; OFAC sanctioned Iran-linked Nobitex for facilitating ransomware-related payments; US agencies (CISA/FBI/NSA/DOE) warn of active attacks against internet-exposed automatic tank gauge (ATG) fuel monitoring systems and ongoing exploitation of Android and Linux kernel bugs; a new single-machine HTTP/2 “Bomb” DoS can crash web servers quickly; Acer is patching maximum-severity zero-days in Wave 7 routers; a VS Code zero-day enables one-click Git
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 63c47bbc89ff2d856f2e6d383e2d0d9d890686610ef7ea8861c862f3602bfa84
- Enrichment time
- 2026-06-04T01:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.