PULSE the living trend engine
◼ Archived Technology 🔮 PULSE predicts: fades by tomorrow

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

Russian hackers are deploying the Starland RAT via trojanized versions of common business tools like Zoom and WebEx to target firms in the US and Europe.

5sources
5articles
3velocity
+0%since first seen
54d agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

📍 How it ended

Russian hackers targeted firms in the US and Europe using trojanized WebEx and Zoom installers to deploy Starland RAT. The financially motivated campaign involved a novel RAT and a bespoke WLDR C2 implant.

The story quieted without a definitive conclusion in the coverage.

Epilogue added 21d ago, after coverage quieted.

The brief

A new cyber campaign attributed to Russian hackers is targeting businesses across the United States and Europe. According to coverage from BleepingComputer and Security Affairs, the attackers are using trojanized installers for popular business communication software, specifically Zoom and WebEx. These fake applications are designed to deploy the Starland Remote Access Trojan (RAT) onto victim systems. The operation is being linked to a specific threat actor identified as UAT-11795, who is utilizing these trojanized tools to gain unauthorized access to corporate environments. Detailed technical analysis provided by the Cisco Talos Blog emphasizes that this activity is part of a financially motivated campaign. Along with the Starland RAT, the threat actor is deploying a bespoke C2 implant known as WLDR.

The Cisco Talos Blog and Intelligent CISO report that the campaign involves the use of novel malware variants. IT Pro notes that Cisco has officially sounded an alarm regarding these threats, highlighting the risk to firms in both the US and Europe that rely on standard remote collaboration software for their daily operations. This trend matters because it weaponizes the inherent trust users place in essential business software. By masquerading as legitimate installers for Zoom and WebEx, the hackers can bypass traditional user scrutiny. The involvement of UAT-11795 and the deployment of the Starland RAT indicate a sophisticated approach to financial gain through corporate infiltration. The use of a bespoke C2 implant further suggests a tailored infrastructure designed to maintain persistence and control over the compromised networks of the affected organizations.

Looking forward, the focus remains on the spread of the Starland RAT and the activity of UAT-11795. Organizations in the US and Europe must monitor for the presence of the WLDR C2 implant. According to the reported findings from Cisco and other security researchers, the primary vector of infection is the installation of fraudulent software updates or apps. Future updates from security outlets like BleepingComputer and the Cisco Talos Blog will likely track whether new trojanized applications are introduced into this specific financially motivated campaign.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 44d ago.

Quick answers

Which software applications are being trojanized?

The hackers are using fake installers for Zoom and WebEx.

Who is the threat actor behind this campaign?

The campaign is attributed to Russian hackers and specifically the actor identified as UAT-11795.

What specific malware is being deployed?

The attackers are deploying the Starland RAT and a bespoke C2 implant called WLDR.

Coverage (5)

Topics

Related trends

\n \n \n \n \n \n \n