Fake Zoom/Webex Installers Drop Starland RAT

Security Affairs · High sophistication
Last updated July 30, 2026

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools like Zoom, Webex, and MobaXterm. Victims are socially engineered via a “ClickFix” style trick into running a command that silently downloads and runs a malicious file, while the installer appears to work normally. The result is remote access and credential/crypto wallet theft, with resilient command-and-control that can fall back to blockchain-hosted instructions.

How the attack worked

A financially motivated group tracked as UAT-11795 has been targeting users in the U.S. and Europe since at least June 2025 with trojanized installers for widely used tools. Instead of relying on obviously suspicious files, the campaign repackages installers for MobaXterm, Cisco Webex, Zoom, DBeaver, and the gaming platform FACEIT so that developers, IT administrators, and other technical staff download what looks like a routine update.

Initial access appears to come through a ClickFix style prompt, where the victim is tricked into running a command that downloads and executes a malicious HTA file silently. That HTA file drops a batch script and the trojanized installer while establishing persistence through a registry Run key that re-executes the HTA at every logon.

Why it succeeded

The core reason this technique works is that the actual software installation proceeds normally, so the victim sees what they expected and has no reason to suspect anything happened. Because the visible outcome matches the expected outcome, users have little reason to question the download source or the extra steps they were asked to perform.

Starland RAT also performs sandbox checks and sets persistence, including a scheduled task with a randomized name and a Startup folder shortcut, before making any network calls. This sequencing helps it avoid early detection in automated analysis environments.

What to watch for

  • Being asked to run a command you did not request, especially as part of a “fix” for an install or access issue
  • Installers from sources you did not verify directly with the vendor
  • Unusual scheduled tasks or Startup entries appearing after a software install
  • Fix instructions that involve script or HTA execution rather than a standard, signed installer

Once active, the RAT performs reconnaissance, enumerates cryptocurrency wallets, takes screenshots, and sends a Telegram notification to an attacker-controlled bot with victim details such as IP address, operating system, and wallet information.

How to build resistance

Organizations should reinforce that legitimate software updates and IT fixes never require running an unfamiliar command from a pop-up, chat, or webpage. Any such request should be verified directly with IT or helpdesk through a known channel before action is taken.

Defenders should also plan for resilient attacker infrastructure. If the primary C2 registration fails, the RAT enables a blockchain-anchored fallback mechanism, so blocking a single domain is not sufficient. Monitoring for unexpected persistence artifacts, such as scheduled tasks following unusual naming patterns, gives another opportunity to catch the activity before data or credentials are exfiltrated. Related techniques include T1204.002, T1547.001, and T1053.005.

Key findings

  • UAT-11795 is described as a “Russian-speaking, financially motivated adversary” targeting the U.S. and Europe since at least June 2025.
  • The campaign uses trojanized installers for legitimate, commonly used software (Zoom, Webex, MobaXterm, DBeaver, FACEIT) so victims see an expected installation and may not suspect compromise.
  • Initial access “appears to come through a ClickFix social engineering technique,” tricking victims into running a command that downloads and executes a malicious HTA file.
  • Starland RAT performs sandbox checks and then sets persistence (scheduled task and Startup shortcut) before network activity, and performs reconnaissance plus crypto wallet enumeration and screenshots.
  • If the primary C2 fails, Starland can use a Polygon blockchain smart contract to retrieve a fallback domain, making simple domain blocking less effective.
  • The malware sends a Telegram notification to attacker-controlled bots with victim details (IP, OS, “Crew ID,” wallets), indicating operator workflow and tracking.

Who’s being targeted

  • Commonly targeted roles: Developers, IT administrators, Engineering, Helpdesk / IT support, Security operations (SOC), End users who install software.
  • Affected industries: IT services, Software development / engineering, Technology companies, Gaming / esports communities.
  • Attack channels: website.
  • Impersonated: Software vendor download page (e.g., Zoom/Webex/MobaXterm), IT support/help article or pop-up “fix” instructions.

Red flags to watch for

  • Installer came from an untrusted or unexpected download source
  • Installer behaves oddly (extra prompts, unexpected files), even if the app installs successfully
  • Security tools warn about an installer that contains scripts or a bundled runtime
  • Being asked to run a command you did not request or do not understand
  • Fix instructions that involve HTA/script execution rather than standard software update paths
  • The “fix” runs without a clear vendor-signed installer or official support ticket
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the ClickFix technique used in this campaign?

ClickFix tricks a victim into running a command that downloads and executes a malicious HTA file silently, which then drops a batch file and a trojanized installer while setting up persistence.

How can trojanized installers infect a device if the software still works?

The actual software installation proceeds normally, so the victim sees what they expected and has no reason to suspect anything happened, even though malicious code was installed alongside the real app.

How does Starland RAT maintain access if its command-and-control is blocked?

If the primary C2 registration fails, the RAT enables a blockchain-anchored fallback mechanism using a Polygon smart contract to retrieve a fallback domain.

Which software was impersonated in this campaign?

The operation distributed trojanized installers for MobaXterm, Cisco Webex, Zoom, DBeaver, and the gaming platform FACEIT.

Read the video transcript

You Google “Zoom download,” click the top result, run the installer… it works. Meeting opens. You think you’re safe. Behind that normal install, a trojanized Zoom or Webex setup quietly drops Starland RAT, used by a Russian‑speaking group called UAT‑11795. It sets a scheduled task like “PythonLauncher-X7Q,” adds a Startup shortcut, and starts hunting your passwords and crypto wallets. The sneaky part is how they get in: a “ClickFix” trick tells you to paste a command from a web page or help pop‑up. That command silently pulls a malicious HTA file, which then drops the fake installer and re-runs itself every time you log in. Here’s the move: if a web page, chat, or pop‑up tells you to run a command or installer for Zoom, Webex, or MobaXterm, stop and contact our IT helpdesk through our official channel before you run anything.

Similar attacks

Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

July 17, 2026
Invoice Phish Leads to Resilient ValleyRAT

Invoice Phish Leads to Resilient ValleyRAT

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

July 31, 2026