UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign — Threadlinqs Intelligence
As of 2026-07-16, UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign is a high-severity malware threat attributed to UAT-11795 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-1413 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: UAT-11795 · Russia · FINANCIAL
Cisco Talos identified UAT-11795, a Russian-speaking financially motivated threat actor, deploying novel Python-based Starland RAT and PowerShell-based WLDR C2 implant alongside CastleStealer and
UAT-11795 is a Russian-speaking, financially motivated threat actor tracked by Cisco Talos, active since at least June 2025, conducting an opportunistic, volume-driven distribution campaign targeting victims primarily in the United States, with secondary targeting in Germany, Romania, and Venezuela. The actor lures victims via ClickFix-style social engineering that delivers a weaponized HTA file executed through mshta.exe. The HTA drops a batch file that downloads a trojanized software installer masquerading as legitimate applications including MobaXterm, Cisco WebEx, Zoom, DBeaver Community Edition, and the FACEIT gaming client. The NSIS-packaged installer executes a Python loader disguised as a LICENSE.txt file, which XOR-decrypts (key 0xC6) and executes the novel Starland RAT entirely in memory.
Starland RAT is a Python-based remote access tool built with defense evasion, system reconnaissance, and browser/cryptocurrency-wallet theft capabilities. It performs sandbox detection by checking for blacklisted usernames (WDAGUtilityAccount) and hostnames (Cuckoo, Any.Run, Joe Sandbox, Hybrid Analysis), checks Zone.Identifier alternate data streams on downloaded files, and establishes persistence via a scheduled task named "PythonLauncher-{3 random chars}" (AtLogOn trigger, RunLevel Highest), a Startup-folder LNK shortcut pointing at pythonw.exe, and an HKCU Run-key registry entry ("MyApp"). It communicates over HTTP POST using XOR encryption (key "helo1") with Base64 encoding on a 50-60 second beacon interval, deriving a hardware ID (HWID) for tracking. Supported commands include shellexecute, x32/x64 shellcode injection, and file download/execute for EXE, MSI, DLL, and ZIP payloads. Notably, Starland RAT implements a fallback command-and-control mechanism using a Polygon blockchain smart contract (address 0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba, function selector 0xc659f3b8) that stores an XOR-encrypted (key "$m7*rYpry3") fallback domain, retrieved via a JSON-RPC eth_call against the Polygon RPC endpoint polygon-rpc[.]com, providing resilience against primary-domain takedown.
Optionally, Starland RAT executes a curl command to download a staged PowerShell-based implant chain culminating in the WLDR C2 Agent. The WLDR chain consists of a Stager, a Downloader, and an Agent, all executed in memory via PowerShell. WLDR communicates over HTTPS with Chrome v124 User-Agent header spoofing, uses AES-256-CBC encryption authenticated with HMAC-SHA256, and derives session keys via PBKDF2-SHA256 with 5,000 iterations from the hardcoded key "odg5t8mvssvh". It polls its C2 every 10 seconds, supports encrypted beaconing and task queuing, and executes additional payloads concurrently via a PowerShell RunspacePool supporting up to 10 threads, with PowerShell background jobs as a fallback execution engine. The implant uses a hardcoded mutex ("f2j398fj239d8j23dkkskskkkkkkkkk") to prevent multiple concurrent instances. A Russian-language VBScript comment ("Добавление команды в автозапуск для текущего пользователя" — "Adding command to autostart for current user") embedded in loader components supports the actor's Russian-speaking attribution.
Alongside Starland RAT and WLDR, the campaign deploys CastleStealer, a .NET infostealer targeting credentials, cryptocurrency wallets (40+ desktop and browser-extension wallets enumerated), and Discord, Telegram, and Steam session data. CastleStealer extracts Chromium and Firefox browser data via direct SQLite database access, supports DPAPI and AES-GCM decryption for credential stores, excludes Russian-locale systems from targeting, and can be delivered as a secondary payload via process injection or PowerShell. The campaign additionally distributes Remcos RAT, a long-abused (since 2016) commercial remote access tool providing keylogging, screen and webcam capture, audio recording, file management, and clipboard monitoring over an encrypted C2 channel.
The actor operates a Telegram-based notification a
Target sectors: cryptocurrency, gaming, general-consumer, cross-sector-opportunistic
Target regions: united states of america, germany, romania, venezuela
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1189, T1059.001, T1059.006, T1059.005, T1218.005, T1204, T1129, T1053.005, T1547.001