Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver Python RAT and Novel WLDR PowerShell C2 Implant — Threadlinqs Intelligence
As of 2026-07-17, Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver Python RAT and Novel WLDR PowerShell C2 Implant is a high-severity malware threat attributed to UAT-11795 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1454 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: UAT-11795 · Russia · FINANCIAL
UAT-11795, a Russian-speaking financially-motivated threat actor active since at least June 2025, lures victims via ClickFix-style social engineering into running an HTA downloader that deploys
UAT-11795 is a financially-motivated, Russian-speaking threat actor first observed by Cisco Talos operating since at least June 2025, targeting users primarily in the United States with secondary activity in Germany, Romania, and Venezuela. The actor's initial access relies on a ClickFix social-engineering technique that tricks victims into copy-pasting and executing a command that invokes mshta.exe to retrieve a weaponized HTA file. The HTA embeds VBScript (containing Russian-language developer comments) that drops a batch file to the user's temp folder and establishes persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key.
The HTA stage then retrieves trojanized NSIS installers that repackage legitimate software — MobaXterm, WebEx, Zoom, DBeaverCE, and FACEIT — bundled with a malicious Python loader disguised as a LICENSE.txt text file. The loader is byte-compiled Python that XOR-decrypts (key 0xC6) and executes an embedded Python RAT in memory, dubbed Starland RAT by Talos. Starland RAT performs sandbox/analysis evasion (checking for WDAGUtilityAccount, Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis artifacts and hardcoded sandbox usernames), establishes persistence via randomized "PythonLauncher-*" scheduled tasks (AtLogOn trigger) and a Startup-folder LNK targeting pythonw.exe, and attempts UAC elevation via ShellExecuteW's "runas" verb.
Once active, Starland RAT enumerates the host (HWID derived from the C: volume serial, RAM, CPU, installed AV products), performs Active Directory reconnaissance (Get-CimInstance, nltest), captures in-memory Base64-encoded PNG screenshots, and scans for 40+ cryptocurrency wallet types alongside browser data. It beacons every 50-60 seconds over XOR-encrypted (key "helo1") Base64 JSON to hardcoded C2 domains windowscreenrepairnearme[.]com and aipythondevs[.]com, and separately reports victim fingerprints and wallet inventories to two Telegram bots (skuefq_bot / ID 8384531459, komandastuk_bot / ID 7993597060) tied to a channel called "stuk komanda" created June 5, 2025. For C2 resilience, Starland queries a Polygon blockchain smart contract (0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba, function selector 0xc659f3b8) via the public polygon-rpc[.]com JSON-RPC endpoint to retrieve an XOR-encrypted fallback C2 domain, and uses api64.ipify[.]org to geolocate victims via public IP. A remote HTTP 403 response acts as a kill switch, triggering self-deletion.
Starland RAT's command set includes shellexecute (arbitrary cmd/PowerShell execution), x32/x64 (APC process-injection shellcode execution), and download (fetch and run EXE/MSI/DLL/ZIP). The shellexecute command can pull a PowerShell stager from eorthopaedics[.]com or sastoro[.]com (under /feed/ and /alpha/ paths) that deploys WLDR, a previously undocumented, entirely in-memory, three-stage PowerShell C2 agent (stager → downloader → agent) protected by a hardcoded mutex ("f2j398fj239d8j23dkkskskkkkkkkkk"). WLDR encrypts traffic with AES-256-CBC plus HMAC-SHA256 (Encrypt-then-MAC), derives keys via PBKDF2-SHA256 (5,000 iterations), binds an HWID to every C2 URL, performs an initial HTTP POST handshake (protocol v2.0.0), polls every 10 seconds over HTTPS spoofing a Chrome/124 User-Agent, and executes tasks through a 10-thread PowerShell RunspacePool (with a background-job fallback), forwarding stdout/stderr/warning streams to the C2 in real time.
Separately, x64 shellcode retrieved from web-devtools[.]com (paths /starlandfox, /x32remka, /dopfile) deploys CastleStealer, an information stealer that decrypts DPAPI- and AES-GCM app-bound-encrypted Chromium and Firefox credential stores, harvests cryptocurrency wallet browser extensions, Discord and Telegram session files, and Steam credentials, exfiltrating over raw TCP sockets; it includes a Russian-locale exclusion check and a hardcoded build-expiry timestamp as anti-analysis measures. The x32 shellcode chain instead deploys a Remcos RAT variant, a commercial RAT abu
Target sectors: general enterprise, gaming, consumer end-user
Target regions: united states of america, germany, romania, venezuela
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.002, T1059.001, T1059.003, T1059.006, T1059.005, T1203, T1204.002, T1053.005, T1129, T1547.001