
Fake Zoom/Webex Installers Drop Starland RAT
Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…
Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software (like Webex, Zoom, and MobaXterm). Once a victim runs the fake installer, a custom remote-access tool (“Starland RAT”) is installed and used to deliver additional malware aimed at stealing valuable credentials and cryptocurrency assets.
Cisco Talos disclosed an active campaign, attributed to a group it tracks as UAT-11795, that has been targeting users in the U.S. and Europe since at least June 2025. The attackers distribute trojanized installers for widely used business tools, including Webex, Zoom, and MobaXterm. When a victim downloads and runs one of these fake installers, it delivers a custom Python-based remote access tool that Talos calls Starland RAT. From there, the attackers use Starland RAT as a gateway to deploy additional payloads, including an in-memory PowerShell command-and-control implant known as the WLDR agent.
The campaign works because it exploits a routine, low-suspicion action: downloading and installing software that employees already trust and use every day. Talos describes the operation as opportunistic, casting a wide net across multiple victim profiles and turning a simple software download into a full compromise. The malware also includes evasive behavior, such as AMSI and ETW bypasses, which helps it avoid detection once it is running on a victim's machine. This combination of a familiar pretext and technically sophisticated evasion makes the attack effective against a broad range of targets, including IT staff, developers, and general employees.
Defenders and end users should be alert to the following signs:
The end goal of this activity is to steal valuable credentials and cryptocurrency assets, making finance and cryptocurrency-related roles particularly attractive targets, though the campaign affects multiple industries.
Organizations can reduce their exposure to this type of attack with a few practical steps:
This technique maps to MITRE ATT&CK T1195.002 (Compromise Software Supply Chain), T1204.002 (User Execution: Malicious File), T1059.001 (PowerShell), and T1053.005 (Scheduled Task).
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Starland RAT is a custom Python-based remote access tool delivered through trojanized installers of popular software like Webex, Zoom, and MobaXterm, according to Cisco Talos.
Cisco Talos attributes the activity to a group it tracks as UAT-11795, which has targeted users in the U.S. and Europe since at least June 2025.
Red flags include downloading installers from unofficial sources, unexpected prompts to run scripts during setup, and unusual PowerShell activity or new scheduled tasks appearing after installation.
The campaign aims to steal valuable credentials and cryptocurrency assets by using Starland RAT as a gateway to deploy additional payloads, including an in-memory PowerShell implant.
You think you're installing Zoom. Instead, you just handed your laptop to Starland RAT. Cisco Talos found a campaign, UAT-11795, using trojanized Zoom, Webex, and MobaXterm installers. You run it, it drops Starland RAT, then silently loads a PowerShell WLDR agent to steal credentials and crypto. The only hint you see: you grabbed the installer from some random site, the setup asks you to run odd 'fix' steps, and afterward you notice weird PowerShell windows flashing or new scheduled tasks you never created. Your move: if you didn’t get Zoom, Webex, or MobaXterm from the company portal or the official site, stop, close it, and report it to IT immediately.

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

Cisco Talos reports a real, financially motivated campaign by a Russian-speaking group (UAT-11795) targeting organizations in the US and Europe. The attackers…

Cisco Talos reports a real, financially motivated campaign where victims are tricked via a “ClickFix” style lure into running a command that downloads a…