THREAT OPS › Threat News › UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
<ul><li>Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.  </li><li>Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starl
MITRE ATT&CK techniques
Indicators of compromise
- 0x6ae382ed2154cc84c6672e4e908cd2c69c1b35baeth
- 138.0.0.0ipv4
- storage.ghost.iodomain
- eorthopaedics.comdomain
- web-devtools.comdomain
- zynaris.iodomain
- sastoro.comdomain
- windowscreenrepairnearme.comdomain
- aipythondevs.comdomain
- polygon-rpc.comdomain
- api64.ipify.orgdomain