Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    IEEE Publishing Ethics Team Upholds Research Integrity

    July 30, 2026

    Why a Tiny Social Media Post Has Mathematicians Rethinking AI

    July 30, 2026

    Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic

    July 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • IEEE Publishing Ethics Team Upholds Research Integrity
    • Why a Tiny Social Media Post Has Mathematicians Rethinking AI
    • Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic
    • Montana’s plan to become an experimental medical hub just pushed forward
    • Detect the Signature of Dark Matter With a DIY Antenna
    • OpenAI’s Hacking Debacle Was a Human Mistake
    • The Download: tricking LLMs, and reviving geothermal plants
    • I Got a Free Meal From a Private Chef—Who Filmed It All to Train Robots
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Russian hackers trojanize WebEx, Zoom apps to push Starland malware
    Cybersecurity

    Russian hackers trojanize WebEx, Zoom apps to push Starland malware

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 16, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hacker
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT.

    Attacks have been occurring since at least June 2025 and have focused on users in the U.S., although victims in Germany, Romania, and Venezuela have been observed as well.

    According to researchers at Cisco Talos, the threat actor distributes the payload via trojanized installers for legitimate software such as MobaXterm, WebEx, Zoom, DBeaver, and FaceIT.

    Although the researchers could not confirm the infection vector, they speculate that the malicious files are likely pushed using the ClickFix method.

    In an analysis published today, Cisco Talos says that the attack starts with an HTA file that retrieves a trojanized NSIS installer containing a Python loader disguised as a text file (LICENSE.txt).

    The loader modifies the Windows Registry to establish persistence and then decrypts and loads the Starland remote access trojan (RAT).

    When launched, Starland checks whether it is running in a sandbox environment, adds scheduled tasks and Startup folder items for persistence, and tries to increase its privileges.

    The malware looks for the following types of data on the compromised system:

    • Browser data and cryptocurrency wallet assets, including more than 40 desktop and browser-extension wallets
    • System details, including the HWID, RAM, processor, operating system, computer name, region, public IP address, and installed antivirus products
    • Active Directory information, including domain structure, domain controllers, and the victim’s domain privileges

    StarlandRAT can also capture screenshots of the victim’s desktop, execute shell commands, inject 32- or 64-bit shellcode, and download additional payloads (EXEs, MSIs, DLLs, ZIPs).

    In the observed attacks, the 64-bit shellcode chain delivers the CastleStealer info-stealer malware, while the 32-bit chain delivers the Remcos remote access trojan (RAT).

    CastleStealer targets browser credentials, cryptocurrency wallet information, Discord and Telegram sessions, Steam credentials, and filesystem files.

    Remcos RAT provides capabilities such as keylogging, webcam and screen capture, audio recording, clipboard monitoring, file management, and remote command execution.

    Overview of the UAT-11795 attack chain
    Source: Cisco Talos

    Cisco Talos highlights that the malware’s command-and-control (C2) communication has a redundancy mechanism if reaching the hardcoded address fails, which involves querying a Polygon smart contract with an XOR-encrypted fallback domain.

    Talos also discovered that UAT-11795 uses a previously undocumented PowerShell C2 framework called WLDR, which uses encrypted (PBKDF2-SHA256) beaconing and communications, operates entirely in memory, and binds payload delivery to each victim’s hardware identifier.

    To defend against UAT-11795 attacks, organizations should use the indicators of compromise IoCs in the Cisco Talos report.

    Users should avoid executing commands found online if they don’t understand what they do and should download software only from confirmed official vendor portals.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    apps hackers malware push Russian Starland trojanize WebEx Zoom
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • IEEE Publishing Ethics Team Upholds Research Integrity
    • Why a Tiny Social Media Post Has Mathematicians Rethinking AI
    • Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic
    • Montana’s plan to become an experimental medical hub just pushed forward
    • Detect the Signature of Dark Matter With a DIY Antenna

    IEEE Publishing Ethics Team Upholds Research Integrity

    July 30, 2026

    Why a Tiny Social Media Post Has Mathematicians Rethinking AI

    July 30, 2026

    Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic

    July 30, 2026

    Montana’s plan to become an experimental medical hub just pushed forward

    July 30, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.