CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2666

As cited

Copy frozen at (site build).

threat intel

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Cisco Talos identified UAT-11795, a Russian-speaking financially motivated threat actor conducting campaigns since at least June 2025 against victims in the U.S. and Europe. The group deploys Starland RAT, a Python-based remote access tool, alongside WLDR, a sophisticated PowerShell-based command-and-control implant featuring encrypted beaconing and task queuing capabilities. The actor distributes trojanized installers of legitimate software such as MobaXterm, WebEx, Zoom, and DBeaver to establish persistence and steal credentials and cryptocurrency assets.

Why it matters: Organizations and users in the U.S. and Europe face credential and cryptocurrency theft risk from trojanized downloads of common developer tools and collaboration platforms, requiring immediate review of installation sources and endpoint detection tuning for Starland RAT and WLDR beaconing patterns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Cisco Talos identified UAT-11795, a Russian-speaking financially motivated threat actor conducting campaigns since at least June 2025 against victims in the U.S. and Europe. The group deploys Starland RAT, a Python-based remote access tool, alongside WLDR, a sophisticated PowerShell-based command-and-control implant featuring encrypted beaconing and task queuing capabilities. The actor distributes trojanized installers of legitimate software such as MobaXterm, WebEx, Zoom, and DBeaver to establish persistence and steal credentials and cryptocurrency assets.

Why it matters: Organizations and users in the U.S. and Europe face credential and cryptocurrency theft risk from trojanized downloads of common developer tools and collaboration platforms, requiring immediate review of installation sources and endpoint detection tuning for Starland RAT and WLDR beaconing patterns.

VendorsCiscoMicrosoftZoom
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary