A financially motivated Russian threat group tracked as UAT-11795 has been found distributing fake versions of trusted software, including WebEx, Zoom, MobaXterm, DBeaver, and FaceIT, to infect Windows systems with a newly discovered malware called Starland RAT. According to Cisco Talos, the campaign has been active since at least June 2025 and has mainly targeted users in the United States, although infections have also been seen in Germany, Romania, and Venezuela.

The attack begins when a victim downloads and runs a trojanized installer that appears to be a legitimate application. Researchers believe the malicious files are likely delivered using the ClickFix social engineering technique, although the exact infection method has not been confirmed. Once launched, the installer secretly loads a hidden Python-based component that prepares the system for the malware.
After execution, the malware modifies Windows Registry settings and creates scheduled tasks and Startup entries to ensure it automatically runs every time the computer starts. It also performs checks to detect whether it is running inside a sandbox or analysis environment and attempts to increase its privileges before continuing with its malicious activities. These steps help the attackers keep long-term access to compromised systems.

Starland RAT is designed to collect a wide range of sensitive information from infected devices. It targets browser credentials, cryptocurrency wallet data from more than 40 desktop and browser-extension wallets, hardware details, operating system information, installed security software, public IP addresses, and Active Directory data such as domain structure and user privileges.
The malware also provides attackers with powerful remote access capabilities. It can capture screenshots, execute shell commands, inject both 32-bit and 64-bit shellcode, and download additional malicious files including executables, DLLs, MSI packages, and ZIP archives. These features allow attackers to expand the compromise and perform further malicious operations on the victim’s computer.

Researchers observed that the malware delivers different payloads depending on the system architecture. On 64-bit systems, it installs CastleStealer, which steals browser passwords, cryptocurrency wallet information, Discord and Telegram sessions, Steam credentials, and files stored on the device. On 32-bit systems, it deploys Remcos RAT, a remote access trojan capable of keylogging, webcam access, screen capture, audio recording, clipboard monitoring, file management, and remote command execution.
Cisco Talos also discovered that Starland RAT uses a resilient command-and-control mechanism. If its primary server cannot be reached, the malware retrieves an encrypted backup domain through a Polygon blockchain smart contract. Researchers also identified a previously undocumented PowerShell-based command-and-control framework called WLDR, which encrypts communications, operates entirely in memory, and ties payload delivery to each victim’s hardware identifier.

Security experts recommend downloading software only from official vendor websites and avoiding installers from unofficial sources or unknown links. Users should also avoid running commands they do not fully understand and organizations should monitor for the indicators of compromise published by Cisco Talos. Following these basic security practices can significantly reduce the risk of falling victim to this Starland malware campaign.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news