Russian hackers trojanize WebEx, Zoom apps to push Starland malware
ID: f67a0450-aa90-59c6-9956-4a2dcb6a3690
STIX ID: report--f67a0450-aa90-59c6-9956-4a2dcb6a3690
Feed Name: Bleeping Computer
Researchers (Cisco Talos) attribute an ongoing campaign by financially motivated Russian actor UAT-11795 that trojanizes legitimate installers (MobaXterm, WebEx, Zoom, DBeaver, FaceIT) to deploy Starland RAT and secondary malware (CastleStealer, Remcos) to harvest browser credentials, cryptocurrency wallets, AD data, and system information; the malware employs persistence, sandbox-evasion, privilege escalation, a Polygon smart-contract fallback for C2, and a novel WLDR in-memory PowerShell C2 framework, and defenders are advised to use provided IoCs, avoid untrusted installers, and monitor for the described TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
