Cisco Talos has linked a Russian speaking, financially motivated threat actor it tracks as UAT-11795 to a campaign running since at least June 2025 that distributes malware through fake installers for widely used business software, including Cisco WebEx, Zoom, the SSH client MobaXterm, the database tool DBeaver, and the gaming platform FACEIT.
According to Talos, initial access relies on ClickFix style social engineering, tricking a user into running a command that downloads a malicious HTA file, which in turn fetches trojanized installers from attacker controlled infrastructure. Once installed, the payloads include a Python based remote access tool Talos calls Starland RAT, a custom PowerShell command and control implant named WLDR, a .NET infostealer dubbed CastleStealer, and the commercial Remcos RAT as a secondary payload. Targeting skews heavily toward the United States, with secondary activity in Germany, Romania, and Venezuela.
The original insight here is what the malware prioritizes: Starland RAT enumerates more than 40 cryptocurrency wallet types and pulls Active Directory data alongside the usual credential and browser theft, and it falls back to a Polygon blockchain smart contract for command and control if its primary channel is blocked, a resilience technique built specifically to survive takedown efforts against conventional C2 infrastructure. CyberTech has tracked a similar shift toward social engineering first initial access in other 2026 campaigns, and this one confirms trojanized developer and collaboration tools are now a standing category alongside phishing and vishing.
Talos has published ClamAV and Snort detection signatures along with a full indicator list so defenders can verify software installers against known good hashes before deployment.
Source: Cisco Talos