← Back to Feed

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

July 16, 2026 · Talos Intelligence · Severity: MEDIUM

Cisco Talos discloses UAT-11795, a Russian-speaking financially motivated adversary targeting users in the US and Europe since June 2025. The group delivers a Python-based RAT called Starland RAT and a PowerShell-based C2 memory implant known as WLDR agent. Their arsenal also includes CastleStealer and Remcos RAT, with a focus on stealing credentials and cryptocurrency assets.

  • Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.  
  • Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.” 
  • The WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads.  
  • UAT-11795 also has CastleStealer and Remcos RAT as alternative payload implants in their arsenal. 
  • The actor targets victims' credentials and cryptocurrency wallet assets, establishing a persistent connection to the victims' machines from the C2 server, with the potential to deliver and execute further payloads. 

Victimology 

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

According to the telemetry data, the infection is predominantly observed in the United States. There are also fewer potential impacts observed in Germany, Romania, and Venezuela, based on the assessment of the passive DNS resolution data of the C2 domains associated with this campaign. 

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Figure 1. Victimology map of this campaign.

Talos has observed that the threat actor in this campaign has utilized trojanized installer lures from software categories including: 

Trojanized installer  

Software name 

Key Takeaways

  • Russian-speaking financially motivated adversary UAT-11795 targets US and Europe since June 2025.
  • Deploys Python-based Starland RAT and sophisticated PowerShell-based WLDR C2 memory implant.
  • Also uses CastleStealer and Remcos RAT, aiming to steal credentials and cryptocurrency wallet assets.
☕ Buy a Coffee