UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
ID: 7ce86c76-d3de-5861-9320-d8066e63934e
STIX ID: report--7ce86c76-d3de-5861-9320-d8066e63934e
Feed Name: Cisco Talos
Cisco Talos discloses a financially motivated, Russian-speaking adversary (UAT-11795) conducting a multi-stage campaign since at least June 2025 that uses trojanized installers and HTA/ClickFix social engineering to deploy a Python-based Starland RAT and a PowerShell in-memory C2 implant (WLDR), with additional payloads (CastleStealer, Remcos); the actors target credentials and cryptocurrency wallets, operate distributed C2 and staging infrastructure (including Telegram bots and a Polygon smart-contract fallback), and employ advanced evasion and in-memory execution techniques, with telemetry indicating primary impact in the United States.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
