UAT-11795 Deploys Starland RAT and WLDR Implant in Financial Theft Campaign

Share:

A financially motivated hacking group is spreading fake installers for well-known software, including
Zoom, WebEx, MobaXterm, and DBeaver. Anyone who runs one of these installers hands the attacker
lasting remote control of the machine, along with stored passwords and cryptocurrency wallets.
Download software only from official vendor sites, and check systems for the indicators listed in this
advisory.

1.Campaign Timeline

UAT-11795 has been active since at least June 2025, when its private Telegram channel “stuk komanda” was created; Cisco Talos published its research on 16 July 2026. Telemetry places most infections in the United States, with fewer in Germany, Romania, and Venezuela. The actor trojanises installers for MobaXterm, Cisco WebEx, Zoom, DBeaver, and FACEIT, a spread that points to an opportunistic, volume-driven operation rather than a single target sector. Talos assesses the operator is Russian-speaking, based on a Russian developer comment in the VBScript and CastleStealer’s Russian-locale exclusion check.

2. Attack Chain

  • Initial access

A ClickFix-style lure, assessed as likely by Talos, tricks the user into running a command that launches mshta.exe to fetch a weaponised HTA file from actor infrastructure.

  • Execution

The HTA’s embedded VBScript drops a batch file that downloads and runs a trojanised installer, then confirms success to an actor-controlled Telegram bot.

  • Persistence

The VBScript sets an HKCU Run key value named MyApp that re-runs the remote HTA at every logon. Starland RAT later adds a PythonLauncher-* scheduled task and a Startup shortcut.

  • Loader

The NSIS installer runs a bundled pythonw.exe against a compiled Python loader disguised as LICENSE.txt,
which XOR-decrypts Starland RAT and executes it in memory.

  • Command and control

The RAT registers the victim over hardware-ID-bound URLs to hardcoded C2 domains, with an encrypted fallback domain stored in a Polygon smart contract. An HTTP 403 response acts as a kill switch.

  • Payload delivery

C2 commands deliver x64 shellcode implanting CastleStealer, x32 shellcode implanting a Remcos RAT variant, or a curl command that stages the WLDR PowerShell agent.

3. Payload Capabilities

  • Starland RAT Python RAT running in memory. Performs host and Active Directory reconnaissance, captures a desktop screenshot, checks for over 40 desktop and browser-extension cryptocurrency wallets, and beacons victim profiles to Telegram bots.
  • WLDR agent Bespoke PowerShell C2 implant operating entirely in memory. Encrypts traffic with AES-256-CBC andHMAC-SHA256, polls every 10 seconds, and streams command output in real time through a 10-thread Runspace engine.
  • CastleStealer .NET stealer delivered via x64 shellcode. Extracts Chromium and Firefox credentials, including app bound encrypted data, plus wallet extensions and Discord, Telegram, and Steam sessions, exfiltrating over a TCP socket.
  • Remcos RAT Commercial RAT delivered via x32 shellcode. Provides keylogging, screen and webcam capture, audio recording, file management, and clipboard monitoring over an encrypted channel.
  • Defence evasion Shellcode loaders resolve Windows APIs by hash at runtime and patch AmsiScanBuffer and EtwEventWrite in memory, blinding AMSI scanning and ETW logging before payload injection.

4. Adversary Toolkit

Tool / IndicatorTypeFunction
Starland RATPythonIn-memory RAT: reconnaissance, wallet enumeration, shellcode injection, payload download and execution.
WLDR agentPowerShellIn-memory C2 implant with encrypted beaconing and Runspace task execution.
WLDR stager and loaderPowerShellObfuscated stages that decrypt and launch the WLDR agent in memory.
CastleStealer.NETInfostealer for browser credentials, wallets, and messaging sessions.
Remcos RATCommercial RATPost-exploitation surveillance: keylogging, screen, webcam, and clipboard capture.
Weaponised HTAHTA / VBScriptDownloads trojanised installers and sets Run-key persistence.
Python loaderPython (compiled)Disguised as LICENSE.txt; XOR-decrypts and executes Starland RAT in memory.
Shellcode loaderx86 / x64 shellcodeAMSI and ETW bypass, then decrypts and injects final payloads.

5. Indicators of Compromise (IOCs)

https://www.virustotal.com/gui/collection/225cae6d05dae346d650754563b5ed3d4b723ffc868bbd9b1e79aa289aa72672/iocs

6. Recommendations

  • Hunt for persistence: scheduled tasks named PythonLauncher-*, Startup shortcuts running pythonw.exe with LICENSE.txt, and the HKCU Run key value MyApp pointing to mshta.exe.
  • Alert on mshta.exe launching remote HTA files and on pythonw.exe starting from installer or temp paths; block HTA execution with attack surface reduction rules where possible.
  • Remove persistence first, then rotate all credentials and move cryptocurrency wallet assets away from any machine confirmed compromised.
  • Deploy the Talos detection content on matching platforms: Snort rules 66787-66790 and 301580, and the published ClamAV signature set.
  • Block the IOCs at their respective controls, using the full VirusTotal collection: https://www.virustotal.com/gui/collection/225cae6d05dae346d650754563b5ed3d4b723ffc868bbd9b1e79aa289aa72672/iocs

7. Sources

  • https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert