talos · Crawled Jul 16, 2026

Begun, the Patch Wars have

12 IoCs
Read original article ↗

AI Summary

Cisco Talos has identified a new campaign by UAT-11795, a financially motivated Russian-speaking threat actor, targeting users in the U.S. and Europe since at least June 2025. The group uses trojanized installers of legitimate software such as Webex, Zoom, and MobaXterm to deliver a custom Python-based remote access tool called 'Starland RAT'. This tool enables deployment of additional payloads, including the in-memory PowerShell-based 'WLDR agent', CastleStealer, and Remcos RAT, to steal credentials and cryptocurrency.

AI-extracted · verify before operational use

Indicators of Compromise 12 extracted

Type Value Detail
SHA-256 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 Details →
MD5 2915b3f8b703eb744fc54c81f4a9c67f Details →
Filename VID001.exe Details →
SHA-256 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f Details →
MD5 38de5b216c33833af710e88f7f64fc98 Details →
Filename SECOH-QAD.exe Details →
SHA-256 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 Details →
MD5 c2efb2dcacba6d3ccc175b6ce1b7ed0a Details →
Filename tmp00055df5.dll Details →
SHA-256 b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a Details →
MD5 0398df5a18f71efcfeef4571a2cef577 Details →
Filename b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a.js Details →