Cisco Talos: What is Starland RAT Malware?

Share this article
Share this article
Prioritise Us on Google
The threat actor in this campaign delivers a Python-based remote access tool (RAT) tracked as Starland RAT and a command-and-control (C2) memory implant known as the WLDR agent | Credit: Cisco Talos
Cisco Talos has uncovered Starland RAT, a custom malware used by UAT-11795 to steal credentials, target crypto wallets and maintain persistent access

A new Python-based remote access tool (RAT) has been uncovered in the wild. 

Tracked as Starland RAT, by Cisco Talos, this new malware was unleashed by a sophisticated, Russian-speaking, financially motivated adversary – UAT-11795. 

Talos says that this notorious group has been operating this malicious campaign targeting users in the US and Europe since at least June 2025.

Starland RAT is capable of giving attackers long-term access to compromised systems while quietly harvesting credentials and cryptocurrency wallet information.

Regions affected | Credit: Cisco Talos

Telemetry data reveals that the primary zone of infection is in the US, though cases were observed in Germany, Romania and Venezuela.

Trojanised software to lure victims

Casting a wide net, these threat actors used trojanised copies of a range of legitimate everyday software to trick users into installing their malware. 

Installers for applications like MobaXterm, Cisco WebEx, Zoom, FACEIT and DBeaverCommunity Edition were among those which had been trojanised. 

By hiding the Starland RAT inside trusted software and likely utilising deceptive ClickFix social engineering tactics, these threat actors are completely bypassing traditional perimeter defences to exploit human psychology rather than software vulnerabilities

Muhammad Yahya Patel, Virtual CISO and Cybersecurity Advisor for EMEA at Huntress

“The breadth of trojanised software across developer tooling, IT administration utilities, enterprise collaboration platforms and a consumer gaming application suggests the actor is operating an opportunistic, volume-driven distribution model targeting multiple victim profiles simultaneously, rather than a single vertical,” the Talos blog says. 

Threat actor infrastructure 

There is distributed infrastructure at play here under the pair of custom-built malware tools designed to maximise persistence and steal valuable data. 

The command-and-control (C2) memory implant, known as the WLDR agent, is extremely sophisticated.

Built with PowerShell, the in-memory command and control implant avoids writing files to disk, making it much harder for traditional security tools to detect. 

Multiple website domains, either hijacked or resembling that of technology startups were used to stage the payload. 

Youtube Placeholder

Interestingly, the C2 URLs included a section that is used to identify what kind of hardware the victim was using, by extracting the serial number of the user’s C drive.

This allows distinct communication depending on the type of the device.

Researchers discovered a fallback command and control mechanism hidden within a Polygon smart contract – a self-executing program that runs on the Polygon blockchain – which allows attackers to retrieve updated server information if their primary infrastructure is disrupted.

Making this a new addition to the growing number of highly resilient threat actor infrastructure.

Attackers also have two Telegram bots under their control.

As Talos notes, these are used to receive the implant’s execution notification beacons and messages with victim’s machine fingerprints and stolen cryptocurrency wallet info. 

Actor-controlled Telegram channel discovered by Talos | Credit: Cisco Talos

Another Telegram channel called stuk komanda has also been found, which Talos says is structured like a C2. 

According to Talos, the group can also swap in alternative malware, including CastleStealer and Remcos RAT, depending on the objective of a campaign.

The initial vector 

The threat intelligence team at Talos thinks that the threat actors could be relying on ClickFix social engineering techniques, where users are enticed to execute a command which downloads and executes a trojanised HTA (html application) file.  

It is from an embedded script in the HTA that a Windows batch file is dropped to the user profile’s application temporary folder, carrying the instructions to download and implant the trojanised installers from the attacker's staging domain to the victim's machine.  

“Financially motivated attackers have long weaponised the very tools our remote and hybrid workers rely on daily, like Zoom and WebEx,” says Muhammad Yahya Patel, Virtual CISO and Cybersecurity Advisor at Huntress

Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress. Credit: LinkedIn

“By hiding the Starland RAT inside trusted software and likely utilising deceptive ClickFix social engineering tactics, these threat actors are completely bypassing traditional perimeter defences to exploit human psychology rather than software vulnerabilities.

“It proves once again that attackers aren't hacking our networks, instead they are tricking our employees.

“Organisations must aggressively enforce Zero Trust application controls and rigorous endpoint monitoring to catch these credential-stealing payloads before they execute.”

The findings once again reinforce the importance of layered cyber security controls.

Downloading software only from verified sources, monitoring for unusual PowerShell activity and implementing strong endpoint detection capabilities can all help reduce the risk posed by campaigns like UAT-11795. 

As threat actors continue to refine their techniques and develop bespoke malware, organisations that combine user awareness with proactive threat monitoring will be in a stronger position to defend against increasingly sophisticated attacks.

Company portals

Executives