Tendvane

← All articles

SecurityJuly 31, 2026

People are still searching for Flash Player - and a fake one is installing a remote-control trojan

Adobe shut Flash Player down in December 2020, and browsers stopped running it years ago. Yet people keep searching for it - to open an old game, a dusty website, some ancient work tool that never got rebuilt. Scammers know that, and they're counting on it.

Researchers at AhnLab's ASEC, whose findings Malwarebytes wrote up on July 31, found a fake installer calling itself AGE Flash Player. Run it and instead of Flash you get AtlasRAT, a remote-access trojan. The clever, nasty part is how it hides: a small program named FlashPlay.Exe rebuilds the real malware in your PC's memory rather than dropping obvious files on disk, which makes it harder for file-scanning antivirus to spot. Once it's running, AtlasRAT logs what you type, hunts for saved passwords, checks which security software you have, and can quietly pull down more malware and survive a reboot. To blend in, its traffic uses a forged certificate reading CN=update.Microsoft.Com - not a real Microsoft signature, just dressed up to look like one.

The simplest defence is knowing you never need Flash Player in 2026. If a site or program insists on it, that's a reason to walk away, not to go hunting for a download. And don't trust the top search result or a "sponsored" link - that's exactly where these fakes sit. Get software from the maker's own site or a source you already trust.

Tendvane gives you that trusted source: it updates your apps through Windows' own package manager (winget) instead of a random installer off a search page, and its Safety check flags unexpected startup programs so you can see if something slipped on.

Sources

Download Tendvane