Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Talos discloses UAT-11795, a Russian-speaking group deploying a novel Starland RAT and custom C2 implant against European and U.S. targets via trojanized collaboration apps—raising supply-chain trust questions for enterprises relying on consumer-grade installers.

Summary written by editorial AI · Source link below

Filed by Cisco Talos1 min readRead at source ↗

Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.

Editorial Analysis

Why it matters

European enterprises using collaboration tools like Zoom and WebEx face direct risk from trojanized installers distributed by a capable financially motivated actor with bespoke tooling that may evade legacy detections.

What to do

Immediately audit software download sources, enforce allowlisted vendor URLs, and deploy Talos-published IOCs across detection stacks.

Board brief

A sophisticated Russian-speaking threat actor is actively targeting European organisations through trojanized business collaboration software, demanding urgent supply-chain verification.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Cisco Talos

External link — opens at Cisco Talos in a new tab.

§
Continue with

More from the Threat Intel Desk