Russian threat actor UAT-11795 uses trojanized Zoom, Webex, and other software installers to deploy Starland RAT

A Russian cybercrime group is spreading fake installers for popular software such as Zoom, Webex, MobaXterm, DBeaver, and FaceIT to infect Windows users with a new backdoor called Starland RAT. Cisco Talos says UAT-11795 has run the campaign since at least June 2025, mainly against U.S. users, using an HTA file and a trojanized NSIS installer to load Starland, persist via Registry and scheduled tasks, and in some cases deliver CastleStealer and Remcos. The malware steals browser and cryptocurrency-wallet data, gathers Active Directory information, and uses a fallback command-and-control method via a Polygon smart contract.
Why it matters: People and organizations can be compromised simply by installing what looks like legitimate remote-work or developer software, leading to stolen passwords, wallet theft, and deeper network access. Defenders should hunt for Talos indicators of compromise, restrict software downloads to verified vendor sources, and warn users against running pasted commands or unofficial installers.

Sources

Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Bill Toulas 2026.07.16 100% relevant
This article establishes a distinct campaign centered on UAT-11795, Starland RAT, and trojanized installers for specific legitimate apps, which does not match an existing tracked story by the same underlying event.
← Back to all stories