Cisco Talos has disclosed details regarding UAT-11795, a sophisticated, Russian-speaking adversary conducting a malicious campaign against users in the United States and Europe since at least June 2026. The group is financially motivated and primarily targets victims in the U.S., with additional impacts observed in Germany, Romania, and Venezuela based on passive DNS resolution data.
The threat actor delivers a Python-based remote access tool tracked as Starland RAT alongside a command-and-control memory implant known as the WLDR agent. The WLDR agent is a PowerShell-based tool featuring encrypted beaconing, task queuing, and a Runspace execution engine for running additional payloads. The group also maintains CastleStealer and Remcos RAT in its arsenal as alternative implants.
Infection vectors include trojanized installers disguised as legitimate software. These lures cover developer tools, IT administration utilities, enterprise collaboration platforms, and consumer gaming applications. Specific examples include modified versions of MobaXterm, Cisco WebEx, Zoom, DBeaver Community Edition, and the FACEIT gaming platform. This broad range suggests an opportunistic, volume-driven distribution model targeting multiple victim profiles simultaneously.
The adversary operates a distributed infrastructure across payload staging and persistent command-and-control domains. Staging domains such as eorthopaedics.com, web-devtools.com, and zynaris.io are designed to blend into legitimate traffic. These domains host PowerShell stage chains, raw shellcode payloads, and trojanized installer lures. The domains windowscreenrepairnearme.com and aipythondevs.com serve as primary command-and-control servers for the Starland RAT.
All command-and-control URLs incorporate a victim hardware identifier derived from the C drive volume serial number. The domains eorthopaedics.com and sastoro.com appear to represent parallel command-and-control infrastructure used for the same campaign, serving hardware-bound unique identifier encrypted envelopes over parameterized URL paths. Further details regarding the group's specific origins or additional targets were not provided.
