talos · Crawled Jul 16, 2026
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
13 IoCs
Read original article ↗
AI Summary
UAT-11795 is a financially motivated, Russian-speaking threat actor active since June 2025, targeting users in the U.S. and Europe. The group deploys a novel Python-based remote access tool (RAT) named Starland RAT and a bespoke PowerShell-based C2 implant, WLDR, using trojanized installers of legitimate software. The campaign focuses on stealing credentials and cryptocurrency wallets, utilizing a multi-stage infection chain involving HTA downloaders, Telegram beacons, and resilient C2 infrastructure, including a fallback mechanism via a Polygon smart contract.
AI-extracted · verify before operational use
Indicators of Compromise 13 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | eorthopaedics[[.]]com | Details → |
| Domain | web-devtools[[.]]com | Details → |
| Domain | zynaris[[.]]io | Details → |
| Domain | sastoro[[.]]com | Details → |
| Domain | windowscreenrepairnearme[[.]]com | Details → |
| Domain | aipythondevs[[.]]com | Details → |
| IP | polygon-rpc[[.]]com | Details → |
| Domain | api64[.]ipify[[.]]org | Details → |
| GitHub Repo | https://github.com/talosintelligence/iocs | Details → |
| Registry User | skuefq_bot | Details → |
| Registry User | komandastuk_bot | Details → |
| Filename | LICENSE.txt | Details → |
| SHA-256 | 0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba | Details → |