logo

New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT

ID: ba1ca50e-ca2e-578f-94aa-26f6e1ea713b

STIX ID: report--ba1ca50e-ca2e-578f-94aa-26f6e1ea713b

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-07-17

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

**Executive summary:** Cisco Talos disclosed a Russian-speaking financially motivated campaign (UAT-11795) that spreads trojanized installers for tools like MobaXterm, Webex, Zoom and others to deploy Starland RAT (Python), the WLDR in-memory PowerShell implant, and additional payloads (CastleStealer, Remcos); the malware uses stealthy anti-analysis checks, persistent scheduled tasks, extensive reconnaissance and credential/wallet theft, and resilient C2 using both hardcoded domains and a Polygon smart-contract fallback with Telegram-based notifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.