logo

New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets

ID: 31aa9780-f28d-5410-a69c-174580b4b467

STIX ID: report--31aa9780-f28d-5410-a69c-174580b4b467

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Mayura Kathir

...
...

Cisco Talos details UAT-11795, a financially motivated Russian-speaking actor conducting a large-scale campaign since June 2025 that uses trojanized installers to deliver a Python-based Starland RAT and a fileless PowerShell WLDR agent to steal browser and desktop cryptocurrency wallets and credentials; the campaign employs in-memory execution, process injection, sandbox-evasion, scheduled task and startup persistence, distributed C2 domains with a Polygon smart-contract fallback, and real-time exfiltration/coordination via Telegram, primarily affecting users in the United States and parts of Europe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.