Executive Summary
UAT-11795, a financially motivated Russian-speaking threat actor, has been conducting a global campaign since June 2025 targeting credentials and cryptocurrency assets. The adversary utilizes 'ClickFix' social engineering to deliver trojanized installers of popular enterprise software like Zoom, WebEx, and MobaXterm. These installers deploy a novel Python-based remote access tool called Starland RAT and a bespoke PowerShell-based memory implant known as the WLDR agent.
The actor demonstrates high technical sophistication by implementing multi-stage infection chains, defense evasion via AMSI/ETW patching, and C2 infrastructure resilience. Notably, the campaign leverages a Polygon blockchain smart contract to store fallback C2 domains, ensuring persistent access even if primary domains are seized. Primary targets are located in the United States, with additional victims identified in Europe and South America.
This threat poses a significant risk to enterprise environments due to the use of legitimate-looking collaboration and IT administration tools as lures. Organizations should prioritize monitoring for unauthorized Python runtime execution from temporary directories and anomalous PowerShell activity involving Runspace manipulation.
Key Details
Threat Name
Starland RAT and WLDR C2 Campaign
Affects
—
Adversary
UAT-11795 Other Adversaries and Aliases: Scattered Spider
MITRE Techniques
Malware/Tools
Starland RAT, WLDR agent, CastleStealer, Remcos RAT, WLDR, remcosRAT
