UAT-11795 Uses Starland RAT and Custom WLDR C2 Implant in Financially Motivated Campaign

Summary
Talos details UAT-11795’s campaign targeting users in the U.S. and Europe with trojanized installers that deliver Starland RAT, a custom PowerShell C2 implant, and other malware to steal credentials and cryptocurrency assets.
Key points
- Talos says the Russian-speaking, financially motivated actor has operated since at least June 2025, with activity observed predominantly in the U.S. and also in Germany, Romania, and Venezuela.
- The campaign uses likely ClickFix lures and trojanized installers for tools including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT to deliver a Python loader and Starland RAT.
- Starland RAT steals browser data and cryptocurrency wallet information, collects host reconnaissance and screenshots, establishes persistence, and can execute commands or download additional payloads.
- A Polygon smart contract provides a fallback method for resolving C2 domains; the actor also uses Telegram bots to receive implant notifications and victim details.
- The custom WLDR PowerShell implant operates in memory, uses encrypted C2 communications, and supports queued tasks and interactive remote PowerShell execution.
- Additional payloads include CastleStealer and Remcos RAT; Talos provides ClamAV signatures and Snort rules for detection and blocking.
Article Details
- Attack Vectors
- Talos assesses that initial access potentially uses ClickFix social engineering to entice users to execute a command that downloads and runs a weaponized HTA.
- Trojanized software installers bundle a Python runtime and a byte-compiled loader disguised as LICENSE.txt. Modified installer instructions execute the loader, which decrypts and runs an embedded payload in memory.
- The initial HTA drops a batch downloader and establishes logon persistence through a user Run registry key.
- The initial implant accepts shell commands, shellcode URLs, and downloadable executable payloads from C2, enabling several additional infection chains.
- A shell-command-driven PowerShell chain retrieves an encrypted, hardware-identifier-bound response and executes a remote access implant entirely in memory.
- Custom shellcode loaders patch security scanning and event tracing functions before decrypting and loading additional payloads.
- Defensive Notes
- The source lists these ClamAV signatures for detection and blocking: Txt.Downloader.Agent-10060312-0, Html.Downloader.Agent-10060313-0, Html.Downloader.Agent-10060314-0, Py.Loader.Agent-10060315-0, Py.Loader.Agent-10060316-0, Ps1.Trojan.Agent-10060317-0, Ps1.Trojan.Agent-10060318-0, Ps1.Trojan.WLDRAgent-10060319-0, Ps1.Downloader.Agent-10060320-0, Win.Trojan.CastleStealer-10060341-0, Win.Trojan.Starland_Installer-10060342-0, Win.Malware.Starland-10060343-0, and Win.Malware.Remka-10060344-0.
- The source lists Snort 2 and Snort 3 rule SIDs 66787–66790 and 301580 for detection and blocking.
- The hardware-bound payload server responds only to requests whose hardware identifier matches a preregistered value, restricting payload retrieval during analysis.
- Username and hostname checks terminate execution in recognized analysis environments; additional checks examine browser-download metadata, locale, and a payload build expiry.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | aipythondevs[.]com | Primary Starland RAT C2 domain using victim hardware identifiers in URL paths. |
| DOMAIN | eorthopaedics[.]com | Payload staging and HWID-bound encrypted C2 infrastructure under /feed/; Talos assesses it is likely a hijacked domain. |
| DOMAIN | sastoro[.]com | Hosts the PowerShell stage chain and HWID-bound encrypted C2 envelopes under /alpha/. |
| DOMAIN | web-devtools[.]com | Attacker staging domain serving raw shellcode under /starlandfox, /x32remka, and /dopfile, plus a compressed archive. |
| DOMAIN | windowscreenrepairnearme[.]com | Primary Starland RAT C2 domain; Talos assesses it is likely a hijacked domain. |
| DOMAIN | zynaris[.]io | Hosts the potentially ClickFix-delivered HTA stager and trojanized installer lures. |
MITRE ATT&CK
T1005 · Data from Local SystemCastleStealer collects cryptocurrency wallet data, Discord and Telegram session files, Steam credentials, and data from targeted filesystem paths.T1016 · System Network Configuration DiscoveryThe WLDR agent uses WMI to gather network adapter configurations.T1018 · Remote System DiscoveryStarland RAT executes nltest /dclist to collect domain controller information.T1027 · Obfuscated Files or InformationThe Python loader contains numerous junk functions and an encrypted embedded payload; the WLDR stager uses obfuscated strings and encrypted next-stage code.T1033 · System Owner/User DiscoveryStarland RAT runs whoami or whoami /all to collect the victim's identity and privilege information.T1036 · MasqueradingThe trojanized installer disguises its compiled Python loader as a license file named LICENSE.txt.T1041 · Exfiltration Over C2 ChannelStarland RAT sends reconnaissance and screenshot data to its C2, and CastleStealer transmits collected material to attacker infrastructure over a TCP socket.T1053.005 · Scheduled TaskStarland RAT creates a PythonLauncher-named scheduled task with an AtLogOn trigger and, when elevated, RunLevel Highest.T1055.004 · Asynchronous Procedure CallStarland RAT executes downloaded 32-bit and 64-bit shellcode using asynchronous procedure call process injection.T1059.001 · PowerShellPowerShell executes reconnaissance commands, the WLDR staging chain, and remotely delivered tasks through Runspace pools or background jobs.T1059.003 · Windows Command ShellA dropped batch file downloads the trojanized installer, and Starland RAT can execute arbitrary commands through cmd /c.T1059.005 · Visual BasicThe HTA executes embedded VBScript that drops a batch file and creates a Run registry entry.T1059.006 · PythonThe installer runs a byte-compiled Python loader through pythonw.exe, and Starland RAT is implemented in Python.T1070.004 · File DeletionStarland RAT deletes its temporary screenshot after encoding it and self-deletes when its C2 returns HTTP 403.T1071.001 · Web ProtocolsStarland RAT and the WLDR agent use HTTP or HTTPS requests for registration, polling, task delivery, and result transmission.T1082 · System Information DiscoveryStarland RAT and the WLDR agent collect hardware identifiers, RAM, OS details, CPU information, and domain membership.T1087.002 · Domain AccountOn domain-joined hosts, Starland RAT executes net user {USERNAME} /dom to obtain domain account information.T1102.001 · Dead Drop ResolverStarland RAT queries a Polygon smart contract to retrieve an encrypted fallback C2 domain when primary registration fails.T1102.003 · One-Way CommunicationAttacker-controlled Telegram bots receive execution notifications, victim fingerprints, and cryptocurrency wallet inventories.T1105 · Ingress Tool TransferThe infection chain downloads installers, shellcode, executable payloads, and PowerShell stages from attacker infrastructure.T1113 · Screen CaptureStarland RAT captures a desktop screenshot, Base64-encodes it, and includes it in victim registration data.T1140 · Deobfuscate/Decode Files or InformationLoaders decrypt embedded payloads using XOR, while the WLDR loader decrypts an encrypted C2 envelope before executing the agent.T1204.002 · Malicious FileVictims execute trojanized software installers that run a bundled malicious Python loader.T1218.005 · MshtaThe infection chain uses mshta.exe to execute a remotely hosted weaponized HTA, including through logon persistence.T1497.001 · System ChecksStarland RAT compares usernames and computer names against known sandbox values and terminates when a match is found.T1518.001 · Security Software DiscoveryBoth implants query installed antivirus products during host reconnaissance.T1547.001 · Registry Run Keys / Startup FolderThe HTA creates HKCU\Software\Microsoft\Windows\CurrentVersion\Run value MyApp, while Starland RAT creates a Startup-folder shortcut.T1555.003 · Credentials from Web BrowsersCastleStealer extracts Chromium and Firefox credentials through direct SQLite database access with credential decryption support.T1562.001 · Disable or Modify ToolsThe shellcode loader patches AmsiScanBuffer to return clean results and EtwEventWrite to suppress event output.T1573.001 · Symmetric CryptographyStarland RAT encrypts C2 messages with XOR, and the WLDR agent encrypts communications with AES-256-CBC using derived session keys.T1620 · Reflective Code LoadingThe custom shellcode loader dispatches decrypted payloads through reflective PE loading or .NET CLR loading in memory.
People
Threat Actors
Malware
CastleStealerUAT-11795 also has CastleStealer and Remcos RAT as alternative payload implants in their arsenal. Remcos RATUAT-11795 also has CastleStealer and Remcos RAT as alternative payload implants in their arsenal. Starland RATUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaignWLDR agentTalos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.”
Vendors
Products
Cisco WebExCisco WebEx and Zoom DBeaverCommunity EditionDBeaverCommunity Edition FACEITFACEIT Microsoft Windowsdbeaver-ce-windows-x86_64.exe MobaXtermMobaXterm Nullsoft Scriptable Install Systemthat the threat actor in this campaign has weaponized software installers by utilizing the Nullsoft Scriptable Install System (NSIS). They have packaged the Python runtime executable “pythonw.exe” along with aPowerShellThe WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads. ZoomWebEx_Client.exe and Zoom installer
Tools
ANY.RUNvictim's computer name against a list of hostnames from recognized sandbox environments, such as Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis. If either check matches, the RAT's execution terminates immediately.ClamAVThe following ClamAV signature detects and blocks this threat: Cuckoothe victim's computer name against a list of hostnames from recognized sandbox environments, such as Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis. If either check matches, the RAT's execution terminatesHybrid Analysisa list of hostnames from recognized sandbox environments, such as Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis. If either check matches, the RAT's execution terminates immediately. Additionally, the RAT examinesJoe Sandboxname against a list of hostnames from recognized sandbox environments, such as Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis. If either check matches, the RAT's execution terminates immediately.SnortThe following Snort Rules Snort 2 and Snort 3 (SIDs) to detect and block this threat: 66787 – 66790 and 301580
Countries
Germanyis predominantly observed in the United States. There are also fewer potential impacts observed in Germany, Romania, and Venezuela, based on the assessment of the passive DNS resolution data of the C2 domainsRomania predominantly observed in the United States. There are also fewer potential impacts observed in Germany, Romania, and Venezuela, based on the assessment of the passive DNS resolution data of the C2 domains associatedUnited StatesAccording to the telemetry data, the infection is predominantly observed in the United States. There are also fewer potential impacts observed in Germany, Romania, and Venezuela, based on the assessment of the passiveVenezuelaobserved in the United States. There are also fewer potential impacts observed in Germany, Romania, and Venezuela, based on the assessment of the passive DNS resolution data of the C2 domains associated with this