UAT-11795 Deploys Starland RAT and WLDR Agent
Score: 9/10

UAT-11795 Deploys Starland RAT and WLDR Agent

Russian-speaking threat actor UAT-11795 is utilizing ClickFix lures and trojanized software to deploy novel Python-based Starland RAT and PowerShell-based WLDR agent for cryptocurrency theft.

Executive Summary

Since June 2025, a Russian-speaking, financially motivated threat actor designated as UAT-11795 has targeted users across the United States and Europe. The campaign leverages sophisticated social engineering, such as ClickFix techniques, to deliver trojanized installers for popular software like MobaXterm, Zoom, and DBeaver. Once executed, these installers deploy a multi-stage infection chain featuring the novel Python-based 'Starland RAT' and a bespoke PowerShell command-and-control (C2) memory implant called the 'WLDR agent.'

The adversary infrastructure is highly resilient, utilizing hijacked domains for staging and a blockchain-anchored fallback mechanism via a Polygon smart contract to maintain C2 persistence. The primary goal of the operation appears to be the systematic theft of credentials and cryptocurrency assets from desktop and browser-based wallets. The use of custom implants alongside established malware like Remcos RAT and CastleStealer demonstrates a high level of operational maturity and a focus on long-term access.

Key Details

Threat Name

UAT-11795 Starland RAT Campaign

Affects

—

Adversary

UAT-11795

Malware/Tools

Starland RAT, WLDR agent, CastleStealer, Remcos RAT, remcosRAT

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth9

Sources