Executive Summary
In June 2025, the Russian threat actor UAT-11795 initiated a campaign targeting users primarily in the United States, with additional victims in Germany, Romania, and Venezuela. The attackers distributed trojanized installers of legitimate software, including WebEx and Zoom, to deploy the Starland RAT malware. This backdoor enabled the exfiltration of browser data, cryptocurrency wallet assets, system details, and Active Directory information. The malware also facilitated remote command execution, screenshot capture, and the deployment of additional payloads such as CastleStealer and Remcos RAT.
This incident underscores the increasing sophistication of supply chain attacks, where trusted software is weaponized to infiltrate systems. The use of trojanized installers highlights the critical need for organizations to enforce strict software sourcing policies and to educate users on the risks of downloading software from unofficial sources.
Why This Matters Now
The UAT-11795 campaign exemplifies the evolving threat landscape, where attackers exploit trusted software channels to distribute malware. As remote work and reliance on collaboration tools like WebEx and Zoom continue to grow, ensuring the integrity of software installations is paramount to prevent unauthorized access and data breaches.
Attack Path Analysis
The attack began with the distribution of trojanized installers for legitimate software, leading to the execution of malicious payloads. The malware then attempted to escalate privileges by modifying system settings and establishing persistence. Subsequently, it moved laterally within the network to access additional systems and data. The compromised systems communicated with command and control servers to receive further instructions and payloads. Sensitive data, including credentials and cryptocurrency wallet information, was exfiltrated. Finally, the attackers achieved their objectives, resulting in financial loss and potential reputational damage.
Kill Chain Progression
Initial Compromise
Description
Attackers distributed trojanized installers for legitimate software such as WebEx and Zoom, leading to the execution of malicious payloads upon installation.
MITRE ATT&CK® Techniques
Compromise Software Supply Chain
Event Triggered Execution: Installer Packages
Masquerading
Command and Scripting Interpreter
File and Directory Discovery
Input Capture: Keylogging
Screen Capture
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Applications and Workloads
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High-value target for cryptocurrency wallet theft and credential harvesting through trojanized software, requiring enhanced egress security and anomaly detection capabilities.
Information Technology/IT
Critical exposure through compromised development tools like MobaXterm and DBeaver, enabling lateral movement and Active Directory reconnaissance in enterprise environments.
Computer Software/Engineering
Elevated risk from trojanized legitimate software distribution affecting developer workflows, requiring zero trust segmentation and encrypted traffic monitoring solutions.
Telecommunications
Vulnerable through compromised WebEx and Zoom applications enabling remote access trojans, necessitating multicloud visibility and threat detection for communication infrastructure.
Sources
- Russian hackers trojanize WebEx, Zoom apps to push Starland malwarehttps://www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/Verified
- UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaignhttps://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial execution may occur, CNSF would likely limit the malware's ability to communicate with other workloads, reducing the potential for further compromise.
Control: Zero Trust Segmentation
Mitigation: Even if the malware gains elevated privileges, Zero Trust Segmentation would likely restrict its access to other critical systems, reducing the scope of potential damage.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely impede the malware's lateral movement by enforcing strict controls on inter-workload communications, thereby reducing the attacker's reach.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely detect and constrain unauthorized outbound communications, thereby limiting the malware's ability to receive further instructions.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit unauthorized data exfiltration by enforcing strict policies on outbound traffic, thereby reducing data loss.
While some impact may occur, the implementation of CNSF controls would likely reduce the overall blast radius, limiting the extent of financial and reputational damage.
Impact at a Glance
Affected Business Functions
- IT Administration
- Software Development
- Enterprise Collaboration
- Online Gaming
Estimated downtime: 7 days
Estimated loss: $500,000
Compromised credentials and cryptocurrency wallet assets from users in the U.S., Germany, Romania, and Venezuela.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Enforce Threat Detection & Anomaly Response mechanisms to identify and mitigate malicious behaviors promptly.
- • Apply Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads.



