The Containment Era is here. →Explore

Executive Summary

In June 2025, the Russian threat actor UAT-11795 initiated a campaign targeting users primarily in the United States, with additional victims in Germany, Romania, and Venezuela. The attackers distributed trojanized installers of legitimate software, including WebEx and Zoom, to deploy the Starland RAT malware. This backdoor enabled the exfiltration of browser data, cryptocurrency wallet assets, system details, and Active Directory information. The malware also facilitated remote command execution, screenshot capture, and the deployment of additional payloads such as CastleStealer and Remcos RAT.

This incident underscores the increasing sophistication of supply chain attacks, where trusted software is weaponized to infiltrate systems. The use of trojanized installers highlights the critical need for organizations to enforce strict software sourcing policies and to educate users on the risks of downloading software from unofficial sources.

Why This Matters Now

The UAT-11795 campaign exemplifies the evolving threat landscape, where attackers exploit trusted software channels to distribute malware. As remote work and reliance on collaboration tools like WebEx and Zoom continue to grow, ensuring the integrity of software installations is paramount to prevent unauthorized access and data breaches.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack highlighted deficiencies in software sourcing policies and endpoint security measures, emphasizing the need for strict controls over software installations and enhanced monitoring for unauthorized applications.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While initial execution may occur, CNSF would likely limit the malware's ability to communicate with other workloads, reducing the potential for further compromise.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Even if the malware gains elevated privileges, Zero Trust Segmentation would likely restrict its access to other critical systems, reducing the scope of potential damage.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-West Traffic Security would likely impede the malware's lateral movement by enforcing strict controls on inter-workload communications, thereby reducing the attacker's reach.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud Visibility & Control would likely detect and constrain unauthorized outbound communications, thereby limiting the malware's ability to receive further instructions.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress Security & Policy Enforcement would likely limit unauthorized data exfiltration by enforcing strict policies on outbound traffic, thereby reducing data loss.

Impact (Mitigations)

While some impact may occur, the implementation of CNSF controls would likely reduce the overall blast radius, limiting the extent of financial and reputational damage.

Impact at a Glance

Affected Business Functions

  • IT Administration
  • Software Development
  • Enterprise Collaboration
  • Online Gaming
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Compromised credentials and cryptocurrency wallet assets from users in the U.S., Germany, Romania, and Venezuela.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement within the network.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
  • Enforce Threat Detection & Anomaly Response mechanisms to identify and mitigate malicious behaviors promptly.
  • Apply Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image