New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
ID: 31aa9780-f28d-5410-a69c-174580b4b467
STIX ID: report--31aa9780-f28d-5410-a69c-174580b4b467
Feed Name: GBHackers
Cisco Talos details UAT-11795, a financially motivated Russian-speaking actor conducting a large-scale campaign since June 2025 that uses trojanized installers to deliver a Python-based Starland RAT and a fileless PowerShell WLDR agent to steal browser and desktop cryptocurrency wallets and credentials; the campaign employs in-memory execution, process injection, sandbox-evasion, scheduled task and startup persistence, distributed C2 domains with a Polygon smart-contract fallback, and real-time exfiltration/coordination via Telegram, primarily affecting users in the United States and parts of Europe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
