Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Russian hackers are deploying the Starland RAT via trojanized versions of common business tools like Zoom and WebEx to target firms in the US and Europe.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
📍 How it ended
Russian hackers targeted firms in the US and Europe using trojanized WebEx and Zoom installers to deploy Starland RAT. The financially motivated campaign involved a novel RAT and a bespoke WLDR C2 implant.
The story quieted without a definitive conclusion in the coverage.
Epilogue added 21d ago, after coverage quieted.
The brief
A new cyber campaign attributed to Russian hackers is targeting businesses across the United States and Europe. According to coverage from BleepingComputer and Security Affairs, the attackers are using trojanized installers for popular business communication software, specifically Zoom and WebEx. These fake applications are designed to deploy the Starland Remote Access Trojan (RAT) onto victim systems. The operation is being linked to a specific threat actor identified as UAT-11795, who is utilizing these trojanized tools to gain unauthorized access to corporate environments. Detailed technical analysis provided by the Cisco Talos Blog emphasizes that this activity is part of a financially motivated campaign. Along with the Starland RAT, the threat actor is deploying a bespoke C2 implant known as WLDR.
The Cisco Talos Blog and Intelligent CISO report that the campaign involves the use of novel malware variants. IT Pro notes that Cisco has officially sounded an alarm regarding these threats, highlighting the risk to firms in both the US and Europe that rely on standard remote collaboration software for their daily operations. This trend matters because it weaponizes the inherent trust users place in essential business software. By masquerading as legitimate installers for Zoom and WebEx, the hackers can bypass traditional user scrutiny. The involvement of UAT-11795 and the deployment of the Starland RAT indicate a sophisticated approach to financial gain through corporate infiltration. The use of a bespoke C2 implant further suggests a tailored infrastructure designed to maintain persistence and control over the compromised networks of the affected organizations.
Looking forward, the focus remains on the spread of the Starland RAT and the activity of UAT-11795. Organizations in the US and Europe must monitor for the presence of the WLDR C2 implant. According to the reported findings from Cisco and other security researchers, the primary vector of infection is the installation of fraudulent software updates or apps. Future updates from security outlets like BleepingComputer and the Cisco Talos Blog will likely track whether new trojanized applications are introduced into this specific financially motivated campaign.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 44d ago.
Quick answers
Which software applications are being trojanized?
The hackers are using fake installers for Zoom and WebEx.
Who is the threat actor behind this campaign?
The campaign is attributed to Russian hackers and specifically the actor identified as UAT-11795.
What specific malware is being deployed?
The attackers are deploying the Starland RAT and a bespoke C2 implant called WLDR.
Coverage (5)
- Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe IT Pro · 55d ago
- Researchers warn of malware campaign using trojanised business software Intelligent CISO · 55d ago
- New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT Security Affairs · 55d ago
- UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos Blog · 55d ago
- Russian hackers trojanize WebEx, Zoom apps to push Starland malware BleepingComputer · 55d ago
Topics
Related trends
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
A Chinese-speaking adversary designated UAT-10147 is scaling server attacks by integrating agentic AI to automate vulnerability exploitation.
CEO who went viral for firing 900 employees on Zoom before Christmas is now mad that he got fired
3 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Doom! Board lowers the boom on Indian-American CEO who fired 900 employees over Zoom
Former Better Home & Finance CEO Vishal Garg is seeking reinstatement after a controversial mass firing of 900 employees via Zoom.
The CEO who fired 900 people on Zoom just before Christmas wants his job back
5 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Critical annotation flaws in Zoom have exposed users to potential remote hijacking risks, prompting urgent security updates.
‘Zoomsday’ hack uncovered using fewer than 20 AI prompts
Zoom annotation flaws could let a meeting participant hijack another attendee's client using fewer than 20 AI prompts.