Chinese hackers use new Atlas RAT malware in European cyberattacks

2026-06-04T01:23:31Z63c47bbc89ff2d856f2e6d383e2d0d9d890686610ef7ea8861c862f3602bfa84
ATGCISAFBINSAOFACacer-wave-7androidatlas-ratchinese-actorscve-2026-8206denial-of-servicefuel-tank-monitoringgithub-token-thefthttp2-bombindustrial-control-systemskirkilinux-kernelminecraft-malware','ai-ransomware-toolkit','edr-evasion'nobitexransomwareratvs-code-zero-dayweedhackwordpresszero-day

What happened

Multiple high-risk cyber events reported: a Chinese-speaking group is deploying a new Atlas RAT and previously undocumented malware in European intrusions; OFAC sanctioned Iran-linked Nobitex for facilitating ransomware-related payments; US agencies (CISA/FBI/NSA/DOE) warn of active attacks against internet-exposed automatic tank gauge (ATG) fuel monitoring systems and ongoing exploitation of Android and Linux kernel bugs; a new single-machine HTTP/2 “Bomb” DoS can crash web servers quickly; Acer is patching maximum-severity zero-days in Wave 7 routers; a VS Code zero-day enables one-click Git

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
63c47bbc89ff2d856f2e6d383e2d0d9d890686610ef7ea8861c862f3602bfa84
Enrichment time
2026-06-04T01:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.