UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Talos discloses UAT-11795, a Russian-speaking group deploying a novel Starland RAT and custom C2 implant against European and U.S. targets via trojanized collaboration apps—raising supply-chain trust questions for enterprises relying on consumer-grade installers.
Summary written by editorial AI · Source link below
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
Editorial Analysis
European enterprises using collaboration tools like Zoom and WebEx face direct risk from trojanized installers distributed by a capable financially motivated actor with bespoke tooling that may evade legacy detections.
Immediately audit software download sources, enforce allowlisted vendor URLs, and deploy Talos-published IOCs across detection stacks.
A sophisticated Russian-speaking threat actor is actively targeting European organisations through trojanized business collaboration software, demanding urgent supply-chain verification.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Cisco Talos in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul