New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT
ID: ba1ca50e-ca2e-578f-94aa-26f6e1ea713b
STIX ID: report--ba1ca50e-ca2e-578f-94aa-26f6e1ea713b
Feed Name: Security Affairs
**Executive summary:** Cisco Talos disclosed a Russian-speaking financially motivated campaign (UAT-11795) that spreads trojanized installers for tools like MobaXterm, Webex, Zoom and others to deploy Starland RAT (Python), the WLDR in-memory PowerShell implant, and additional payloads (CastleStealer, Remcos); the malware uses stealthy anti-analysis checks, persistent scheduled tasks, extensive reconnaissance and credential/wallet theft, and resilient C2 using both hardcoded domains and a Polygon smart-contract fallback with Telegram-based notifications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
