A new malware family, Starland RAT, has emerged, developed by a Russian-speaking group identified as UAT-11795. This campaign targets Windows users, particularly cryptocurrency holders in the U.S. and Europe. The malware is distributed through fake software installers for popular applications such as Zoom and WebEx. Starland RAT is capable of stealing credentials and accessing cryptocurrency wallets.
It employs a sophisticated infection process involving a trojanized installer and capabilities for remote control and data exfiltration. Cisco Talos, which disclosed the threat, advises users to download software only from official sites to avoid infection.