
Fake Zoom/Webex Installers Drop Starland RAT
Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…
Cisco Talos reports a real, financially motivated campaign where victims are tricked via a “ClickFix” style lure into running a command that downloads a weaponized HTA file. That HTA then installs trojanized versions of legitimate software (e.g., WebEx/Zoom/MobaXterm) that deploy Starland RAT and other payloads to steal credentials and crypto wallets and keep remote access.
This campaign, attributed by Cisco Talos to a financially motivated actor tracked as UAT-11795, relies on a ClickFix style lure. Victims encounter a prompt that entices them to execute a command in order to "fix" a supposed problem. That command stealthily downloads and executes a remotely hosted weaponized HTA file through mshta.exe, Microsoft's HTML Application Host. From there, the infection chain installs trojanized versions of legitimate, familiar software, including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT. Once run, these installers deploy Starland RAT and other payloads that steal credentials and cryptocurrency wallet assets while maintaining remote access for the attacker.
The attack succeeds by exploiting trust in two ways. First, ClickFix prompts frame malicious command execution as a routine troubleshooting step, something many users are conditioned to do without question. Second, the trojanized installers mimic tools that employees and developers already expect to download and run regularly, such as WebEx or Zoom. This combination lowers suspicion at both the initial command stage and the software installation stage, letting the malware slip past casual scrutiny.
Organizations can reduce exposure to this style of attack with a few practical habits:
Because this campaign blends a believable troubleshooting pretext with trojanized versions of everyday software, awareness of both stages, the command prompt and the installer itself, is key to catching it early.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a lure that convinces a user to execute a command, believing it will fix an issue, which instead stealthily downloads and runs a weaponized HTA file via mshta.exe.
Talos observed trojanized installers masquerading as common tools including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT.
Starland RAT steals victims' credentials and cryptocurrency wallet assets and can download and execute additional payloads on the infected machine.
General employees, IT/helpdesk staff, developers, and anyone who manages cryptocurrency wallets are all targeted by these lures.
Imagine a website pops up: “Fix required, please execute this command to complete the repair.” That’s the ClickFix trick UAT-11795 is using: you run their command, mshta.exe quietly pulls a weaponized HTA, and it installs a trojanized “Zoom” or “WebEx_Client.exe” behind the scenes. Here’s the nasty part: that fake installer drops Starland RAT, which digs into your saved passwords and cryptocurrency wallets, then quietly pings a Telegram bot to report back. If any website tells you to run a command to ‘fix’ something or download a Zoom, WebEx, or MobaXterm installer, stop and contact IT using our normal help desk before you click or run anything.

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

Cisco Talos reports a real, financially motivated campaign by a Russian-speaking group (UAT-11795) targeting organizations in the US and Europe. The attackers…

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…