Trojanized Zoom/Webex Installers Spread Starland RAT

Cisco Talos · High sophistication
Last updated July 30, 2026

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software (like Webex, Zoom, and MobaXterm). Once a victim runs the fake installer, a custom remote-access tool (“Starland RAT”) is installed and used to deliver additional malware aimed at stealing valuable credentials and cryptocurrency assets.

How the attack worked

Cisco Talos disclosed an active campaign, attributed to a group it tracks as UAT-11795, that has been targeting users in the U.S. and Europe since at least June 2025. The attackers distribute trojanized installers for widely used business tools, including Webex, Zoom, and MobaXterm. When a victim downloads and runs one of these fake installers, it delivers a custom Python-based remote access tool that Talos calls Starland RAT. From there, the attackers use Starland RAT as a gateway to deploy additional payloads, including an in-memory PowerShell command-and-control implant known as the WLDR agent.

Why it succeeded

The campaign works because it exploits a routine, low-suspicion action: downloading and installing software that employees already trust and use every day. Talos describes the operation as opportunistic, casting a wide net across multiple victim profiles and turning a simple software download into a full compromise. The malware also includes evasive behavior, such as AMSI and ETW bypasses, which helps it avoid detection once it is running on a victim's machine. This combination of a familiar pretext and technically sophisticated evasion makes the attack effective against a broad range of targets, including IT staff, developers, and general employees.

What to watch for

Defenders and end users should be alert to the following signs:

  • Installers obtained from an unofficial or unexpected download source rather than a company portal or official vendor site
  • Unexpected prompts to run scripts or additional "fix" steps during what should be a routine installation
  • Unusual PowerShell activity after installation, particularly scripts executing from memory
  • Unexpected scheduled tasks appearing on a system shortly after a software install
  • Suspicious execution of mshta.exe, which security teams should actively monitor

The end goal of this activity is to steal valuable credentials and cryptocurrency assets, making finance and cryptocurrency-related roles particularly attractive targets, though the campaign affects multiple industries.

How to build resistance

Organizations can reduce their exposure to this type of attack with a few practical steps:

  • Require employees to download software only from approved sources, such as an internal company portal or official vendor sites
  • Train staff that normal-looking software installs can still be a trap, and encourage them to pause and verify before running an installer that feels off
  • Educate users specifically on ClickFix-style social engineering tactics and the risks of unofficial software downloads
  • Encourage rapid reporting of unusual system behavior, especially unexpected PowerShell activity or new scheduled tasks, so security operations can investigate quickly

This technique maps to MITRE ATT&CK T1195.002 (Compromise Software Supply Chain), T1204.002 (User Execution: Malicious File), T1059.001 (PowerShell), and T1053.005 (Scheduled Task).

Key findings

  • Cisco Talos disclosed an active campaign by UAT-11795 targeting users in the U.S. and Europe since at least June 2025.
  • Attackers use trojanized installers for well-known tools (Webex, Zoom, MobaXterm) to get victims to install malware.
  • Initial malware (“Starland RAT”) is used as a gateway to deploy additional payloads, including an in-memory PowerShell C2 implant (“WLDR agent”).
  • The campaign includes evasive behavior (AMSI and ETW bypasses) and aims to steal credentials and cryptocurrency assets.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Developers, Helpdesk/Service Desk, Security Operations.
  • Affected industries: Multiple / cross-industry, Finance, Cryptocurrency.
  • Attack channels: website.
  • Impersonated: Zoom / Webex / MobaXterm software installer.

Red flags to watch for

  • Installer obtained from an unofficial or unexpected download source
  • Unexpected prompts to run scripts or additional "fix" steps during installation
  • After installation, unusual PowerShell activity or scheduled tasks appear
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Starland RAT?

Starland RAT is a custom Python-based remote access tool delivered through trojanized installers of popular software like Webex, Zoom, and MobaXterm, according to Cisco Talos.

Who is behind this campaign?

Cisco Talos attributes the activity to a group it tracks as UAT-11795, which has targeted users in the U.S. and Europe since at least June 2025.

What should employees watch for?

Red flags include downloading installers from unofficial sources, unexpected prompts to run scripts during setup, and unusual PowerShell activity or new scheduled tasks appearing after installation.

What is the goal of the attackers?

The campaign aims to steal valuable credentials and cryptocurrency assets by using Starland RAT as a gateway to deploy additional payloads, including an in-memory PowerShell implant.

Read the video transcript

You think you're installing Zoom. Instead, you just handed your laptop to Starland RAT. Cisco Talos found a campaign, UAT-11795, using trojanized Zoom, Webex, and MobaXterm installers. You run it, it drops Starland RAT, then silently loads a PowerShell WLDR agent to steal credentials and crypto. The only hint you see: you grabbed the installer from some random site, the setup asks you to run odd 'fix' steps, and afterward you notice weird PowerShell windows flashing or new scheduled tasks you never created. Your move: if you didn’t get Zoom, Webex, or MobaXterm from the company portal or the official site, stop, close it, and report it to IT immediately.

Similar attacks

Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

July 17, 2026