bleeping-computer · Crawled Jul 16, 2026

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

1 IoCs
Read original article ↗

AI Summary

A Russian financially motivated threat actor, UAT-11795, has been conducting attacks since at least June 2025 by distributing trojanized installers of legitimate software such as WebEx, Zoom, and MobaXterm to deploy the Starland RAT. The malware establishes persistence, performs reconnaissance, steals credentials and cryptocurrency, and can deploy additional payloads like CastleStealer and Remcos RAT. The campaign targets users in the U.S., Germany, Romania, and Venezuela, using sophisticated techniques including registry manipulation, sandbox detection, and encrypted C2 communications via a PowerShell framework called WLDR.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename LICENSE.txt Details →