Cisco Talos: What is Starland RAT Malware?

A new Python-based remote access tool (RAT) has been uncovered in the wild.
Tracked as Starland RAT, by Cisco Talos, this new malware was unleashed by a sophisticated, Russian-speaking, financially motivated adversary – UAT-11795.
Talos says that this notorious group has been operating this malicious campaign targeting users in the US and Europe since at least June 2025.
Starland RAT is capable of giving attackers long-term access to compromised systems while quietly harvesting credentials and cryptocurrency wallet information.
Telemetry data reveals that the primary zone of infection is in the US, though cases were observed in Germany, Romania and Venezuela.
Trojanised software to lure victims
Casting a wide net, these threat actors used trojanised copies of a range of legitimate everyday software to trick users into installing their malware.
Installers for applications like MobaXterm, Cisco WebEx, Zoom, FACEIT and DBeaverCommunity Edition were among those which had been trojanised.
By hiding the Starland RAT inside trusted software and likely utilising deceptive ClickFix social engineering tactics, these threat actors are completely bypassing traditional perimeter defences to exploit human psychology rather than software vulnerabilities
“The breadth of trojanised software across developer tooling, IT administration utilities, enterprise collaboration platforms and a consumer gaming application suggests the actor is operating an opportunistic, volume-driven distribution model targeting multiple victim profiles simultaneously, rather than a single vertical,” the Talos blog says.
Threat actor infrastructure
There is distributed infrastructure at play here under the pair of custom-built malware tools designed to maximise persistence and steal valuable data.
The command-and-control (C2) memory implant, known as the WLDR agent, is extremely sophisticated.
Built with PowerShell, the in-memory command and control implant avoids writing files to disk, making it much harder for traditional security tools to detect.
Multiple website domains, either hijacked or resembling that of technology startups were used to stage the payload.
Interestingly, the C2 URLs included a section that is used to identify what kind of hardware the victim was using, by extracting the serial number of the user’s C drive.
This allows distinct communication depending on the type of the device.
Researchers discovered a fallback command and control mechanism hidden within a Polygon smart contract – a self-executing program that runs on the Polygon blockchain – which allows attackers to retrieve updated server information if their primary infrastructure is disrupted.
Making this a new addition to the growing number of highly resilient threat actor infrastructure.
Attackers also have two Telegram bots under their control.
As Talos notes, these are used to receive the implant’s execution notification beacons and messages with victim’s machine fingerprints and stolen cryptocurrency wallet info.
Another Telegram channel called stuk komanda has also been found, which Talos says is structured like a C2.
According to Talos, the group can also swap in alternative malware, including CastleStealer and Remcos RAT, depending on the objective of a campaign.
The initial vector
The threat intelligence team at Talos thinks that the threat actors could be relying on ClickFix social engineering techniques, where users are enticed to execute a command which downloads and executes a trojanised HTA (html application) file.
It is from an embedded script in the HTA that a Windows batch file is dropped to the user profile’s application temporary folder, carrying the instructions to download and implant the trojanised installers from the attacker's staging domain to the victim's machine.
“Financially motivated attackers have long weaponised the very tools our remote and hybrid workers rely on daily, like Zoom and WebEx,” says Muhammad Yahya Patel, Virtual CISO and Cybersecurity Advisor at Huntress.
“By hiding the Starland RAT inside trusted software and likely utilising deceptive ClickFix social engineering tactics, these threat actors are completely bypassing traditional perimeter defences to exploit human psychology rather than software vulnerabilities.
“It proves once again that attackers aren't hacking our networks, instead they are tricking our employees.
“Organisations must aggressively enforce Zero Trust application controls and rigorous endpoint monitoring to catch these credential-stealing payloads before they execute.”
The findings once again reinforce the importance of layered cyber security controls.
Downloading software only from verified sources, monitoring for unusual PowerShell activity and implementing strong endpoint detection capabilities can all help reduce the risk posed by campaigns like UAT-11795.
As threat actors continue to refine their techniques and develop bespoke malware, organisations that combine user awareness with proactive threat monitoring will be in a stronger position to defend against increasingly sophisticated attacks.
Cisco
Huntress
- JadePuffer: Sysdig Sniffs Out the First Agentic RansomwareHacking & Malware
- Bear Necessities: Google on The Russian Sphere of InfluenceCyber Security
- Endava and Wiz Redefine Enterprise Multi-cloud & AI SecurityCloud Security
- How CoreView Helps HALO Secure Global Microsoft 365 EstateCyber Security





