logo

Russian Hackers Deploy Starland RAT via Trojans in WebEx and Zoom Installers

ID: 97c6f114-b016-5aab-a6cf-6e8a5371973f

STIX ID: report--97c6f114-b016-5aab-a6cf-6e8a5371973f

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

...
...

Cisco Talos reports that Russian-linked actor UAT-11795 has been distributing trojanized installers for legitimate software (e.g., WebEx, Zoom) since at least June 2025 to deploy the Starland RAT; the campaign uses an HTA to fetch a trojanized NSIS installer containing a disguised Python loader, establishes persistence, steals browser credentials and cryptocurrency wallet data, and employs an undocumented in-memory PowerShell C2 framework named WLDR. The activity primarily targets users in the U.S. with some victims in Europe and Venezuela, and Cisco Talos has released IoCs and recommended mitigations such as obtaining software only from official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.