
ClickFix Lures Push Trojanized Apps, Starland RAT
Cisco Talos reports a real, financially motivated campaign where victims are tricked via a “ClickFix” style lure into running a command that downloads a…
Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools like Zoom, Webex, and MobaXterm. Victims are socially engineered via a “ClickFix” style trick into running a command that silently downloads and runs a malicious file, while the installer appears to work normally. The result is remote access and credential/crypto wallet theft, with resilient command-and-control that can fall back to blockchain-hosted instructions.
A financially motivated group tracked as UAT-11795 has been targeting users in the U.S. and Europe since at least June 2025 with trojanized installers for widely used tools. Instead of relying on obviously suspicious files, the campaign repackages installers for MobaXterm, Cisco Webex, Zoom, DBeaver, and the gaming platform FACEIT so that developers, IT administrators, and other technical staff download what looks like a routine update.
Initial access appears to come through a ClickFix style prompt, where the victim is tricked into running a command that downloads and executes a malicious HTA file silently. That HTA file drops a batch script and the trojanized installer while establishing persistence through a registry Run key that re-executes the HTA at every logon.
The core reason this technique works is that the actual software installation proceeds normally, so the victim sees what they expected and has no reason to suspect anything happened. Because the visible outcome matches the expected outcome, users have little reason to question the download source or the extra steps they were asked to perform.
Starland RAT also performs sandbox checks and sets persistence, including a scheduled task with a randomized name and a Startup folder shortcut, before making any network calls. This sequencing helps it avoid early detection in automated analysis environments.
Once active, the RAT performs reconnaissance, enumerates cryptocurrency wallets, takes screenshots, and sends a Telegram notification to an attacker-controlled bot with victim details such as IP address, operating system, and wallet information.
Organizations should reinforce that legitimate software updates and IT fixes never require running an unfamiliar command from a pop-up, chat, or webpage. Any such request should be verified directly with IT or helpdesk through a known channel before action is taken.
Defenders should also plan for resilient attacker infrastructure. If the primary C2 registration fails, the RAT enables a blockchain-anchored fallback mechanism, so blocking a single domain is not sufficient. Monitoring for unexpected persistence artifacts, such as scheduled tasks following unusual naming patterns, gives another opportunity to catch the activity before data or credentials are exfiltrated. Related techniques include T1204.002, T1547.001, and T1053.005.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
ClickFix tricks a victim into running a command that downloads and executes a malicious HTA file silently, which then drops a batch file and a trojanized installer while setting up persistence.
The actual software installation proceeds normally, so the victim sees what they expected and has no reason to suspect anything happened, even though malicious code was installed alongside the real app.
If the primary C2 registration fails, the RAT enables a blockchain-anchored fallback mechanism using a Polygon smart contract to retrieve a fallback domain.
The operation distributed trojanized installers for MobaXterm, Cisco Webex, Zoom, DBeaver, and the gaming platform FACEIT.
You Google “Zoom download,” click the top result, run the installer… it works. Meeting opens. You think you’re safe. Behind that normal install, a trojanized Zoom or Webex setup quietly drops Starland RAT, used by a Russian‑speaking group called UAT‑11795. It sets a scheduled task like “PythonLauncher-X7Q,” adds a Startup shortcut, and starts hunting your passwords and crypto wallets. The sneaky part is how they get in: a “ClickFix” trick tells you to paste a command from a web page or help pop‑up. That command silently pulls a malicious HTA file, which then drops the fake installer and re-runs itself every time you log in. Here’s the move: if a web page, chat, or pop‑up tells you to run a command or installer for Zoom, Webex, or MobaXterm, stop and contact our IT helpdesk through our official channel before you run anything.

Cisco Talos reports a real, financially motivated campaign where victims are tricked via a “ClickFix” style lure into running a command that downloads a…

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…