UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
July 16, 2026 · Talos Intelligence · Severity: MEDIUM
A financially motivated Russian-speaking threat actor, tracked as UAT-11795, has been conducting a campaign targeting users in the U.S. and Europe since at least June 2025. The group deploys a Python-based remote access trojan (RAT) called "Starland RAT" and a sophisticated PowerShell-based C2 memory implant known as "WLDR agent," which features encrypted beaconing, task queuing, and a Runspace execution engine for additional payloads. UAT-11795 also uses CastleStealer and Remcos RAT as alternative payloads, aiming to steal credentials and cryptocurrency wallet assets while maintaining persistent access to victims' machines. The campaign primarily targets victims in the U.S., with fewer infections observed in Germany, Romania, and Venezuela. The threat actor distributes trojanized installers, disguising malware as legitimate software to trick users into downloading malicious payloads. This campaign highlights the growing sophistication of financially motivated cybercriminals, leveraging custom-built tools to evade detection and maintain long-term access to compromised systems. Organizations and individuals in affected regions should remain vigilant against suspicious software downloads and phishing attempts.
- Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
- Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.”
- The WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads.
- UAT-11795 also has CastleStealer and Remcos RAT as alternative payload implants in their arsenal.
- The actor targets victims' credentials and cryptocurrency wallet assets, establishing a persistent connection to the victims' machines from the C2 server, with the potential to deliver and execute further payloads.
Victimology

According to the telemetry data, the infection is predominantly observed in the United States. There are also fewer potential impacts observed in Germany, Romania, and Venezuela, based on the assessment of the passive DNS resolution data of the C2 domains associated with this campaign.

Talos has observed that the threat actor in this campaign has utilized trojanized installer lures from software categories including:
Trojanized installer | Software name | Key Takeaways
|