UAT-11795 Deploys Starland RAT and WLDR Backdoor Through Trojanized Software Installers
ID: 4a4172ed-5f16-570f-89dc-db6c6f3c0dfb
STIX ID: report--4a4172ed-5f16-570f-89dc-db6c6f3c0dfb
Feed Name: Cyber Press
Cisco Talos reports a large-scale financially motivated campaign, tracked as UAT-11795, active since June 2025 that distributes trojanized installers (NSIS-wrapped) to deploy a Python-based Starland RAT and a fileless PowerShell WLDR agent; the malware performs extensive reconnaissance, credential and cryptocurrency wallet theft (including deploying CastleStealer and Remcos), persists via scheduled tasks/startup shortcuts, and uses encrypted C2 with a Polygon smart-contract fallback and Telegram-based victim tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
