Russian hackers trojanize WebEx, Zoom apps to push Starland malware

Cybersecurity researchers have uncovered a sophisticated campaign of financially motivated attacks by Russian hackers using trojanized software to deploy a new backdoor called Starland RAT. The malware is designed to steal sensitive information and cryptocurrency from unsuspecting victims, with a focus on users in the United States but also affecting those in Germany, Romania, and Venezuela.

At the heart of this campaign is a threat actor tracked as UAT-11795, which has been distributing trojanized installers for legitimate software such as WebEx, Zoom, MobaXterm, DBeaver, and FaceIT. While researchers at Cisco Talos couldn’t confirm the exact infection vector, they suspect that malicious files are being pushed using a method called ClickFix. This involves tricking users into downloading and running potentially malicious software, which can then establish a foothold on the compromised system.

Once installed, the Starland RAT malware checks whether it’s running in a sandbox environment and attempts to increase its privileges. It then proceeds to gather sensitive information from the victim’s computer, including browser data, cryptocurrency wallet assets, system details, and Active Directory information. The malware can also capture screenshots of the desktop, execute shell commands, inject malicious code, and download additional payloads.

What makes this campaign particularly concerning is the fact that Starland RAT has a redundancy mechanism for command-and-control communication. If it fails to reach the hardcoded address, it will query a Polygon smart contract with an XOR-encrypted fallback domain. This level of sophistication demonstrates the resourcefulness and determination of the threat actor behind UAT-11795.

To make matters worse, Cisco Talos discovered that UAT-11795 uses a previously undocumented PowerShell C2 framework called WLDR. This framework operates entirely in memory, binds payload delivery to each victim’s hardware identifier, and uses encrypted beaconing and communications.

In order to defend against these attacks, organizations should use the indicators of compromise (IoCs) outlined in the Cisco Talos report. Users can also take simple precautions such as downloading software only from confirmed official vendor portals and avoiding executing commands found online if they don’t understand what they do. By being more vigilant about software downloads and command execution, we can significantly reduce our vulnerability to these types of attacks.

Ultimately, this campaign highlights the importance of staying one step ahead of sophisticated threat actors. By regularly testing our security layers through breach and attack simulation, we can ensure that our detection tools are up to date and effective in preventing successful attacks from slipping through the net.


Source: Bleeping Computer — 2026-07-16