ClickFix Lures Push Trojanized Apps, Starland RAT

Cisco Talos · High sophistication
Last updated July 30, 2026

Cisco Talos reports a real, financially motivated campaign where victims are tricked via a “ClickFix” style lure into running a command that downloads a weaponized HTA file. That HTA then installs trojanized versions of legitimate software (e.g., WebEx/Zoom/MobaXterm) that deploy Starland RAT and other payloads to steal credentials and crypto wallets and keep remote access.

How the Attack Worked

This campaign, attributed by Cisco Talos to a financially motivated actor tracked as UAT-11795, relies on a ClickFix style lure. Victims encounter a prompt that entices them to execute a command in order to "fix" a supposed problem. That command stealthily downloads and executes a remotely hosted weaponized HTA file through mshta.exe, Microsoft's HTML Application Host. From there, the infection chain installs trojanized versions of legitimate, familiar software, including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT. Once run, these installers deploy Starland RAT and other payloads that steal credentials and cryptocurrency wallet assets while maintaining remote access for the attacker.

Why It Succeeded

The attack succeeds by exploiting trust in two ways. First, ClickFix prompts frame malicious command execution as a routine troubleshooting step, something many users are conditioned to do without question. Second, the trojanized installers mimic tools that employees and developers already expect to download and run regularly, such as WebEx or Zoom. This combination lowers suspicion at both the initial command stage and the software installation stage, letting the malware slip past casual scrutiny.

What to Watch For

  • Any prompt asking you to run a command or script to "fix" a problem, especially outside of IT-led troubleshooting.
  • Unexpected use of mshta.exe or other scripting utilities triggered from a website or installer.
  • Installers for common tools (WebEx, Zoom, MobaXterm, DBeaver, FACEIT) obtained from a source other than the official vendor.
  • Unusual persistence entries or repeated prompts after reboot or login following a software install.
  • Any unexpected network beaconing activity following installation, which may indicate the malware confirming execution to its operator.

How to Build Resistance

Organizations can reduce exposure to this style of attack with a few practical habits:

  • Train employees to treat any "fix" that requires running a command as suspicious, and to verify through known IT channels before acting.
  • Reinforce that software should only be downloaded from official vendor sites, never from links in prompts or unsolicited messages.
  • Encourage extra caution among developers and IT staff, who are often targeted with installer lures for tools they use daily, such as MobaXterm or DBeaver.
  • Remind users who manage cryptocurrency wallets that these assets, along with browser-stored credentials, are explicit targets in campaigns like this one, warranting additional verification before installing any new tool.

Because this campaign blends a believable troubleshooting pretext with trojanized versions of everyday software, awareness of both stages, the command prompt and the installer itself, is key to catching it early.

Key findings

  • Talos attributes the activity to “UAT-11795,” described as “Russian-speaking” and “financially motivated,” targeting the U.S. and parts of Europe since at least June 2025.
  • Initial access is described as a “ClickFix social engineering technique” that “entices the user to execute a command,” leading to execution of a weaponized HTA via “mshta.exe.”
  • The campaign distributes trojanized installers masquerading as common tools (MobaXterm, WebEx, Zoom, DBeaver, FACEIT).
  • Starland RAT is used to steal “victims' credentials and cryptocurrency wallet assets” and can download/execute additional payloads.
  • Infrastructure includes multiple staging/C2 domains and Telegram bots used for notifications and stolen information.

Who’s being targeted

  • Commonly targeted roles: All employees, IT/Helpdesk, Developers/Engineering, Users who manage cryptocurrency wallets.
  • Affected industries: Technology / IT administration, Software development, Enterprise collaboration, Gaming / consumers.
  • Attack channels: website.
  • Impersonated: Software/support prompt presented as a “fix” (ClickFix-style), Legitimate software vendor download page (look-alike or staged download).

Red flags to watch for

  • Being asked to run a command to “fix” something
  • A browser/website instructing use of mshta.exe or running scripts
  • Unfamiliar download that triggers an installer unexpectedly
  • Installer source is not the official vendor site
  • Unexpected behavior during install (silent script activity)
  • Generic persistence names (e.g., “MyApp”) or repeated prompts on reboot/login
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a ClickFix social engineering technique?

It is a lure that convinces a user to execute a command, believing it will fix an issue, which instead stealthily downloads and runs a weaponized HTA file via mshta.exe.

What software was trojanized in this campaign?

Talos observed trojanized installers masquerading as common tools including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT.

What does Starland RAT do once installed?

Starland RAT steals victims' credentials and cryptocurrency wallet assets and can download and execute additional payloads on the infected machine.

Who should be most concerned about this attack?

General employees, IT/helpdesk staff, developers, and anyone who manages cryptocurrency wallets are all targeted by these lures.

Read the video transcript

Imagine a website pops up: “Fix required, please execute this command to complete the repair.” That’s the ClickFix trick UAT-11795 is using: you run their command, mshta.exe quietly pulls a weaponized HTA, and it installs a trojanized “Zoom” or “WebEx_Client.exe” behind the scenes. Here’s the nasty part: that fake installer drops Starland RAT, which digs into your saved passwords and cryptocurrency wallets, then quietly pings a Telegram bot to report back. If any website tells you to run a command to ‘fix’ something or download a Zoom, WebEx, or MobaXterm installer, stop and contact IT using our normal help desk before you click or run anything.

Similar attacks

Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

July 17, 2026
Invoice Phish Leads to Resilient ValleyRAT

Invoice Phish Leads to Resilient ValleyRAT

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

July 31, 2026