Activity timeline
UAT-11795 appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1005 Data from Local System — Collectionobserved in 3 of 3 tracked threats
- T1008 Fallback Channels — Command and Controlobserved in 3 of 3 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1033 System Owner/User Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 3 tracked threats
- T1053.005 Scheduled Task — Persistenceobserved in 3 of 3 tracked threats
- T1055 Process Injection — Privilege Escalationobserved in 3 of 3 tracked threats
- T1056.001 Keylogging — Collectionobserved in 3 of 3 tracked threats
- T1059.001 PowerShell — Executionobserved in 3 of 3 tracked threats
- T1059.005 Visual Basic — Executionobserved in 3 of 3 tracked threats
- T1059.006 Python — Executionobserved in 3 of 3 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 3 of 3 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1102.002 Bidirectional Communication — Command and Controlobserved in 3 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
Tracked threats
- Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver Python RAT and Novel WLDR PowerShell C2 ImplantHIGH
- UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated CampaignHIGH
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 ImplantHIGH