UAT-11795 Deploys Starland RAT and WLDR Backdoor Through Trojanized Software Installers
Cisco Talos has uncovered a new financially motivated threat cluster, tracked as UAT-11795, that has been conducting a large-scale malware campaign targeting users across the United States and parts o

Cisco Talos has uncovered a new financially motivated threat cluster, tracked as UAT-11795, that has been conducting a large-scale malware campaign targeting users across the United States and parts of Europe since June 2025. The campaign leverages trojanized software installers to distribute a multi-stage infection chain involving a custom Python-based remote access trojan (RAT) called […] The post UAT-11795 Deploys Starland RAT and WLDR Backdoor Through Trojanized Software Installers appeared first on Cyber Security News.
Cisco Talos has uncovered a new financially motivated threat cluster, tracked as UAT-11795, that has been conducting a large-scale malware campaign targeting users across the United States and parts of Europe since June 2025. The campaign leverages trojanized software installers to distribute a multi-stage infection chain involving a custom Python-based remote access trojan (RAT) called Starland RAT and a sophisticated PowerShell memory implant known as the WLDR agent. The attack begins with social engineering, likely using ClickFix-style lures that trick users into executing malicious commands. This leads to the download of a weaponized HTA file via mshta.exe, which silently installs trojanized versions of legitimate software. Observed lures include widely used tools such as MobaXterm, Zoom, WebEx, and DBeaver, as well as the FACEIT gaming platform. UAT-11795 Spreads Dual Backdoors These installers are modified using the Nullsoft Scriptable Install System (NSIS) and include a hidden Python runtime, along with a malicious loader disguised as a harmless file such as “LICENSE.txt.” Once executed, the loader decrypts and launches Starland RAT directly in memory using XOR-based obfuscation. This broad targeting across IT tools, developer platforms, and consumer applications indicates a volume-driven distribution model aimed at maximizing infections rather than focusing on a single industry vertical. Cisco Umbrella domain resolution statistics for the malicious domains during the research window (Source: talosintelligence) Once deployed, Starland RAT establishes persistence through scheduled tasks and startup shortcuts and attempts privilege escalation. It performs extensive system reconnaissance, collecting hardware identifiers, antivirus details, Active Directory information, and screenshots. It also scans for over 40 cryptocurrency wallets and browser extensions, highlighting a clear financial motive. The malware communicates with command-and-control (C2) servers using encrypted HTTP requests and uniquely identifies victims via hardware-based IDs. Notably, it incorporates a blockchain-based fallback mechanism that uses a Polygon smart contract to retrieve backup C2 infrastructure, dynamically enhancing resilience against takedowns. Starland RAT supports multiple command types, enabling attackers to execute shell commands, inject shellcode, or download additional payloads. For example, 64-bit shellcode infections deploy CastleStealer, a . NET-based infostealer targeting browser credentials, crypto wallets, and messaging platforms. Meanwhile, 32-bit systems may be targeted by the Remcos RAT, a well-known surveillance and remote control tool. Actor-controlled Telegram channel (Source: talosintelligence) In parallel, the attackers deploy the WLDR agent, a fileless, PowerShell-based backdoor that operates entirely in memory. Delivered via an obfuscated PowerShell stager, WLDR uses AES-256-CBC with HMAC authentication and a Runspace-based execution engine that supports concurrent task processing. An example of its capability is real-time command execution: attackers can send PowerShell scripts that execute across multiple threads, with output streamed back incrementally, enabling interactive control over infected systems, talosintelligence said. The campaign’s infrastructure is distributed across staging and C2 domains designed to mimic legitimate services, including developer portals and startup platforms. Some domains appear to be hijacked, while others are purpose-built. Additionally, Telegram bots are used for real-time victim tracking, exfiltrating system fingerprints and cryptocurrency data immediately after infection. Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs The post UAT-11795 Deploys Starland RAT and WLDR Backdoor Through Trojanized Software Installers appeared first on Cyber Security News.
Join the Discussion
Comments coming soon. Follow us on social media for real-time discussions.


