DEV Community

Mark0
Mark0

Posted on

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Cisco Talos has identified a new Russian-speaking, financially motivated threat actor designated as UAT-11795, which has been targeting users in the U.S. and Europe since mid-2025. The adversary employs an opportunistic distribution model, using "ClickFix" social engineering and trojanized installers for legitimate software—including MobaXterm, WebEx, and Zoom—to deliver a sophisticated malware suite. This suite features the "Starland RAT," a Python-based remote access tool, and the "WLDR agent," a bespoke PowerShell-based memory implant designed for encrypted beaconing and modular task execution.

The campaign is notable for its resilient infrastructure and advanced defense evasion. UAT-11795 utilizes Telegram bots for victim notification and leverages a Polygon smart contract to store fallback C2 domains, ensuring persistent connectivity even if primary domains are seized. The malware includes capabilities for system reconnaissance, credential harvesting, and the theft of cryptocurrency assets from over 40 different wallet types. Additionally, the actor utilizes custom shellcode loaders to deploy secondary payloads like CastleStealer and Remcos RAT, incorporating bypasses for AMSI and ETW to remain undetected by security products.


Read Full Article

Top comments (0)