logo

UAT-11795 Deploys Starland RAT and WLDR Backdoor Through Trojanized Software Installers

ID: 4a4172ed-5f16-570f-89dc-db6c6f3c0dfb

STIX ID: report--4a4172ed-5f16-570f-89dc-db6c6f3c0dfb

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Varshini

...
...

Cisco Talos reports a large-scale financially motivated campaign, tracked as UAT-11795, active since June 2025 that distributes trojanized installers (NSIS-wrapped) to deploy a Python-based Starland RAT and a fileless PowerShell WLDR agent; the malware performs extensive reconnaissance, credential and cryptocurrency wallet theft (including deploying CastleStealer and Remcos), persists via scheduled tasks/startup shortcuts, and uses encrypted C2 with a Polygon smart-contract fallback and Telegram-based victim tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.