Russian Hackers Deploy Starland RAT via Trojans in WebEx and Zoom Installers
ID: 97c6f114-b016-5aab-a6cf-6e8a5371973f
STIX ID: report--97c6f114-b016-5aab-a6cf-6e8a5371973f
Feed Name: ThreatCluster
Cisco Talos reports that Russian-linked actor UAT-11795 has been distributing trojanized installers for legitimate software (e.g., WebEx, Zoom) since at least June 2025 to deploy the Starland RAT; the campaign uses an HTA to fetch a trojanized NSIS installer containing a disguised Python loader, establishes persistence, steals browser credentials and cryptocurrency wallet data, and employs an undocumented in-memory PowerShell C2 framework named WLDR. The activity primarily targets users in the U.S. with some victims in Europe and Venezuela, and Cisco Talos has released IoCs and recommended mitigations such as obtaining software only from official sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
