UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
July 16, 2026 · Talos Intelligence · Severity: MEDIUM
Cisco Talos discloses UAT-11795, a Russian-speaking financially motivated adversary targeting users in the US and Europe since June 2025. The group delivers a Python-based RAT called Starland RAT and a PowerShell-based C2 memory implant known as WLDR agent. Their arsenal also includes CastleStealer and Remcos RAT, with a focus on stealing credentials and cryptocurrency assets.
- Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
- Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.”
- The WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads.
- UAT-11795 also has CastleStealer and Remcos RAT as alternative payload implants in their arsenal.
- The actor targets victims' credentials and cryptocurrency wallet assets, establishing a persistent connection to the victims' machines from the C2 server, with the potential to deliver and execute further payloads.
Victimology

According to the telemetry data, the infection is predominantly observed in the United States. There are also fewer potential impacts observed in Germany, Romania, and Venezuela, based on the assessment of the passive DNS resolution data of the C2 domains associated with this campaign.

Talos has observed that the threat actor in this campaign has utilized trojanized installer lures from software categories including:
Trojanized installer | Software name | Key Takeaways
|