UAT-11795 Uses Starland RAT and Custom WLDR C2 Implant in Financially Motivated Campaign

· Original article ↗

Summary

Talos details UAT-11795’s campaign targeting users in the U.S. and Europe with trojanized installers that deliver Starland RAT, a custom PowerShell C2 implant, and other malware to steal credentials and cryptocurrency assets.

Key points

  • Talos says the Russian-speaking, financially motivated actor has operated since at least June 2025, with activity observed predominantly in the U.S. and also in Germany, Romania, and Venezuela.
  • The campaign uses likely ClickFix lures and trojanized installers for tools including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT to deliver a Python loader and Starland RAT.
  • Starland RAT steals browser data and cryptocurrency wallet information, collects host reconnaissance and screenshots, establishes persistence, and can execute commands or download additional payloads.
  • A Polygon smart contract provides a fallback method for resolving C2 domains; the actor also uses Telegram bots to receive implant notifications and victim details.
  • The custom WLDR PowerShell implant operates in memory, uses encrypted C2 communications, and supports queued tasks and interactive remote PowerShell execution.
  • Additional payloads include CastleStealer and Remcos RAT; Talos provides ClamAV signatures and Snort rules for detection and blocking.

Article Details

Attack Vectors
  • Talos assesses that initial access potentially uses ClickFix social engineering to entice users to execute a command that downloads and runs a weaponized HTA.
  • Trojanized software installers bundle a Python runtime and a byte-compiled loader disguised as LICENSE.txt. Modified installer instructions execute the loader, which decrypts and runs an embedded payload in memory.
  • The initial HTA drops a batch downloader and establishes logon persistence through a user Run registry key.
  • The initial implant accepts shell commands, shellcode URLs, and downloadable executable payloads from C2, enabling several additional infection chains.
  • A shell-command-driven PowerShell chain retrieves an encrypted, hardware-identifier-bound response and executes a remote access implant entirely in memory.
  • Custom shellcode loaders patch security scanning and event tracing functions before decrypting and loading additional payloads.
Defensive Notes
  • The source lists these ClamAV signatures for detection and blocking: Txt.Downloader.Agent-10060312-0, Html.Downloader.Agent-10060313-0, Html.Downloader.Agent-10060314-0, Py.Loader.Agent-10060315-0, Py.Loader.Agent-10060316-0, Ps1.Trojan.Agent-10060317-0, Ps1.Trojan.Agent-10060318-0, Ps1.Trojan.WLDRAgent-10060319-0, Ps1.Downloader.Agent-10060320-0, Win.Trojan.CastleStealer-10060341-0, Win.Trojan.Starland_Installer-10060342-0, Win.Malware.Starland-10060343-0, and Win.Malware.Remka-10060344-0.
  • The source lists Snort 2 and Snort 3 rule SIDs 66787–66790 and 301580 for detection and blocking.
  • The hardware-bound payload server responds only to requests whose hardware identifier matches a preregistered value, restricting payload retrieval during analysis.
  • Username and hostname checks terminate execution in recognized analysis environments; additional checks examine browser-download metadata, locale, and a payload build expiry.

Indicators of compromise

TypeIndicatorContext
DOMAINaipythondevs[.]comPrimary Starland RAT C2 domain using victim hardware identifiers in URL paths.
DOMAINeorthopaedics[.]comPayload staging and HWID-bound encrypted C2 infrastructure under /feed/; Talos assesses it is likely a hijacked domain.
DOMAINsastoro[.]comHosts the PowerShell stage chain and HWID-bound encrypted C2 envelopes under /alpha/.
DOMAINweb-devtools[.]comAttacker staging domain serving raw shellcode under /starlandfox, /x32remka, and /dopfile, plus a compressed archive.
DOMAINwindowscreenrepairnearme[.]comPrimary Starland RAT C2 domain; Talos assesses it is likely a hijacked domain.
DOMAINzynaris[.]ioHosts the potentially ClickFix-delivered HTA stager and trojanized installer lures.

MITRE ATT&CK

T1005 · Data from Local SystemCastleStealer collects cryptocurrency wallet data, Discord and Telegram session files, Steam credentials, and data from targeted filesystem paths.T1016 · System Network Configuration DiscoveryThe WLDR agent uses WMI to gather network adapter configurations.T1018 · Remote System DiscoveryStarland RAT executes nltest /dclist to collect domain controller information.T1027 · Obfuscated Files or InformationThe Python loader contains numerous junk functions and an encrypted embedded payload; the WLDR stager uses obfuscated strings and encrypted next-stage code.T1033 · System Owner/User DiscoveryStarland RAT runs whoami or whoami /all to collect the victim's identity and privilege information.T1036 · MasqueradingThe trojanized installer disguises its compiled Python loader as a license file named LICENSE.txt.T1041 · Exfiltration Over C2 ChannelStarland RAT sends reconnaissance and screenshot data to its C2, and CastleStealer transmits collected material to attacker infrastructure over a TCP socket.T1053.005 · Scheduled TaskStarland RAT creates a PythonLauncher-named scheduled task with an AtLogOn trigger and, when elevated, RunLevel Highest.T1055.004 · Asynchronous Procedure CallStarland RAT executes downloaded 32-bit and 64-bit shellcode using asynchronous procedure call process injection.T1059.001 · PowerShellPowerShell executes reconnaissance commands, the WLDR staging chain, and remotely delivered tasks through Runspace pools or background jobs.T1059.003 · Windows Command ShellA dropped batch file downloads the trojanized installer, and Starland RAT can execute arbitrary commands through cmd /c.T1059.005 · Visual BasicThe HTA executes embedded VBScript that drops a batch file and creates a Run registry entry.T1059.006 · PythonThe installer runs a byte-compiled Python loader through pythonw.exe, and Starland RAT is implemented in Python.T1070.004 · File DeletionStarland RAT deletes its temporary screenshot after encoding it and self-deletes when its C2 returns HTTP 403.T1071.001 · Web ProtocolsStarland RAT and the WLDR agent use HTTP or HTTPS requests for registration, polling, task delivery, and result transmission.T1082 · System Information DiscoveryStarland RAT and the WLDR agent collect hardware identifiers, RAM, OS details, CPU information, and domain membership.T1087.002 · Domain AccountOn domain-joined hosts, Starland RAT executes net user {USERNAME} /dom to obtain domain account information.T1102.001 · Dead Drop ResolverStarland RAT queries a Polygon smart contract to retrieve an encrypted fallback C2 domain when primary registration fails.T1102.003 · One-Way CommunicationAttacker-controlled Telegram bots receive execution notifications, victim fingerprints, and cryptocurrency wallet inventories.T1105 · Ingress Tool TransferThe infection chain downloads installers, shellcode, executable payloads, and PowerShell stages from attacker infrastructure.T1113 · Screen CaptureStarland RAT captures a desktop screenshot, Base64-encodes it, and includes it in victim registration data.T1140 · Deobfuscate/Decode Files or InformationLoaders decrypt embedded payloads using XOR, while the WLDR loader decrypts an encrypted C2 envelope before executing the agent.T1204.002 · Malicious FileVictims execute trojanized software installers that run a bundled malicious Python loader.T1218.005 · MshtaThe infection chain uses mshta.exe to execute a remotely hosted weaponized HTA, including through logon persistence.T1497.001 · System ChecksStarland RAT compares usernames and computer names against known sandbox values and terminates when a match is found.T1518.001 · Security Software DiscoveryBoth implants query installed antivirus products during host reconnaissance.T1547.001 · Registry Run Keys / Startup FolderThe HTA creates HKCU\Software\Microsoft\Windows\CurrentVersion\Run value MyApp, while Starland RAT creates a Startup-folder shortcut.T1555.003 · Credentials from Web BrowsersCastleStealer extracts Chromium and Firefox credentials through direct SQLite database access with credential decryption support.T1562.001 · Disable or Modify ToolsThe shellcode loader patches AmsiScanBuffer to return clean results and EtwEventWrite to suppress event output.T1573.001 · Symmetric CryptographyStarland RAT encrypts C2 messages with XOR, and the WLDR agent encrypts communications with AES-256-CBC using derived session keys.T1620 · Reflective Code LoadingThe custom shellcode loader dispatches decrypted payloads through reflective PE loading or .NET CLR loading in memory.

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Related Articles