talos · Crawled Jul 16, 2026

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

13 IoCs
Read original article ↗

AI Summary

UAT-11795 is a financially motivated, Russian-speaking threat actor active since June 2025, targeting users in the U.S. and Europe. The group deploys a novel Python-based remote access tool (RAT) named Starland RAT and a bespoke PowerShell-based C2 implant, WLDR, using trojanized installers of legitimate software. The campaign focuses on stealing credentials and cryptocurrency wallets, utilizing a multi-stage infection chain involving HTA downloaders, Telegram beacons, and resilient C2 infrastructure, including a fallback mechanism via a Polygon smart contract.

AI-extracted · verify before operational use

Indicators of Compromise 13 extracted

Type Value Detail
Domain eorthopaedics[[.]]com Details →
Domain web-devtools[[.]]com Details →
Domain zynaris[[.]]io Details →
Domain sastoro[[.]]com Details →
Domain windowscreenrepairnearme[[.]]com Details →
Domain aipythondevs[[.]]com Details →
IP polygon-rpc[[.]]com Details →
Domain api64[.]ipify[[.]]org Details →
GitHub Repo https://github.com/talosintelligence/iocs Details →
Registry User skuefq_bot Details →
Registry User komandastuk_bot Details →
Filename LICENSE.txt Details →
SHA-256 0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba Details →