talos · Crawled Jul 16, 2026
Begun, the Patch Wars have
12 IoCs
Read original article ↗
AI Summary
Cisco Talos has identified a new campaign by UAT-11795, a financially motivated Russian-speaking threat actor, targeting users in the U.S. and Europe since at least June 2025. The group uses trojanized installers of legitimate software such as Webex, Zoom, and MobaXterm to deliver a custom Python-based remote access tool called 'Starland RAT'. This tool enables deployment of additional payloads, including the in-memory PowerShell-based 'WLDR agent', CastleStealer, and Remcos RAT, to steal credentials and cryptocurrency.
AI-extracted · verify before operational use
Indicators of Compromise 12 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | Details → |
| MD5 | 2915b3f8b703eb744fc54c81f4a9c67f | Details → |
| Filename | VID001.exe | Details → |
| SHA-256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | Details → |
| MD5 | 38de5b216c33833af710e88f7f64fc98 | Details → |
| Filename | SECOH-QAD.exe | Details → |
| SHA-256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | Details → |
| MD5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | Details → |
| Filename | tmp00055df5.dll | Details → |
| SHA-256 | b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a | Details → |
| MD5 | 0398df5a18f71efcfeef4571a2cef577 | Details → |
| Filename | b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a.js | Details → |