Threat Actor
UAT-11795
- First Reported
- Jul 16, 2026
- Latest Reported
- Jul 16, 2026
Reported Context (1)
- Talos identifies this Russian-speaking, financially motivated adversary as active since at least June 2025, distributing trojanized installers and implants to steal credentials and cryptocurrency assets. UAT-11795 Uses Starland RAT and Custom WLDR C2 Implant in Financially Motivated Campaign
Malware (4)
People (2)
MITRE ATT&CK (31)
Vendors (1)
Products (8)
Tools (6)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.