securityonline.info 7/22/2026, 2:31:18 PM · external

Starland RAT lurks in fake Zoom installers, stealing crypto data

Starland RAT lurks in fake Zoom installers, stealing crypto data
Developing story malware 2 articles tracked
UAT-11795 distributes Starland RAT via fake Zoom and Webex installers
CyberSIXT Evidence Panel
Threat Actor
UAT-11795

A new malware family, Starland RAT, has emerged, developed by a Russian-speaking group identified as UAT-11795. This campaign targets Windows users, particularly cryptocurrency holders in the U.S. and Europe. The malware is distributed through fake software installers for popular applications such as Zoom and WebEx. Starland RAT is capable of stealing credentials and accessing cryptocurrency wallets.

It employs a sophisticated infection process involving a trojanized installer and capabilities for remote control and data exfiltration. Cisco Talos, which disclosed the threat, advises users to download software only from official sites to avoid infection.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline