Executive Summary
Since June 2025, a Russian-speaking, financially motivated threat actor designated as UAT-11795 has targeted users across the United States and Europe. The campaign leverages sophisticated social engineering, such as ClickFix techniques, to deliver trojanized installers for popular software like MobaXterm, Zoom, and DBeaver. Once executed, these installers deploy a multi-stage infection chain featuring the novel Python-based 'Starland RAT' and a bespoke PowerShell command-and-control (C2) memory implant called the 'WLDR agent.'
The adversary infrastructure is highly resilient, utilizing hijacked domains for staging and a blockchain-anchored fallback mechanism via a Polygon smart contract to maintain C2 persistence. The primary goal of the operation appears to be the systematic theft of credentials and cryptocurrency assets from desktop and browser-based wallets. The use of custom implants alongside established malware like Remcos RAT and CastleStealer demonstrates a high level of operational maturity and a focus on long-term access.
