logo

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

ID: f67a0450-aa90-59c6-9956-4a2dcb6a3690

STIX ID: report--f67a0450-aa90-59c6-9956-4a2dcb6a3690

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Bill Toulas

...
...

Researchers (Cisco Talos) attribute an ongoing campaign by financially motivated Russian actor UAT-11795 that trojanizes legitimate installers (MobaXterm, WebEx, Zoom, DBeaver, FaceIT) to deploy Starland RAT and secondary malware (CastleStealer, Remcos) to harvest browser credentials, cryptocurrency wallets, AD data, and system information; the malware employs persistence, sandbox-evasion, privilege escalation, a Polygon smart-contract fallback for C2, and a novel WLDR in-memory PowerShell C2 framework, and defenders are advised to use provided IoCs, avoid untrusted installers, and monitor for the described TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.