UAT-11795 Deploys Starland RAT via Trojanized Software
Score: 9/10

UAT-11795 Deploys Starland RAT via Trojanized Software

Russian-speaking actor UAT-11795 is targeting US and European users with trojanized installers for MobaXterm, WebEx, and Zoom to deploy the novel Starland RAT and WLDR PowerShell agent.

Executive Summary

UAT-11795, a financially motivated Russian-speaking threat actor, has been conducting a global campaign since June 2025 targeting credentials and cryptocurrency assets. The adversary utilizes 'ClickFix' social engineering to deliver trojanized installers of popular enterprise software like Zoom, WebEx, and MobaXterm. These installers deploy a novel Python-based remote access tool called Starland RAT and a bespoke PowerShell-based memory implant known as the WLDR agent.

The actor demonstrates high technical sophistication by implementing multi-stage infection chains, defense evasion via AMSI/ETW patching, and C2 infrastructure resilience. Notably, the campaign leverages a Polygon blockchain smart contract to store fallback C2 domains, ensuring persistent access even if primary domains are seized. Primary targets are located in the United States, with additional victims identified in Europe and South America.

This threat poses a significant risk to enterprise environments due to the use of legitimate-looking collaboration and IT administration tools as lures. Organizations should prioritize monitoring for unauthorized Python runtime execution from temporary directories and anomalous PowerShell activity involving Runspace manipulation.

Key Details

Threat Name

Starland RAT and WLDR C2 Campaign

Affects

—

Adversary

UAT-11795 Other Adversaries and Aliases: Scattered Spider

Malware/Tools

Starland RAT, WLDR agent, CastleStealer, Remcos RAT, WLDR, remcosRAT

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth9

Sources