Particle.news
Download on the App Store

Russian-Speaking Actor Trojanizes Popular Installers to Deploy Starland RAT

Cisco Talos’ July 16 technical report warns the campaign harvests browser credentials and desktop crypto wallets while using a blockchain fallback and an in-memory PowerShell C2 to avoid detection.

Overview

  • Cisco Talos published a detailed analysis on July 16 attributing the campaign to a financially motivated Russian-speaking group tracked as UAT-11795 and naming the primary backdoor Starland RAT.
  • Initial compromise begins with an HTA that fetches a trojanized NSIS installer; that installer runs a Python loader disguised as LICENSE.txt which establishes persistence and decrypts Starland.
  • Starland performs sandbox checks, creates scheduled tasks and Startup shortcuts for persistence, enumerates system and Active Directory details, and searches for browser data and more than 40 desktop and extension cryptocurrency wallets.
  • After initial execution the actor delivers secondary tools: a 64-bit path drops CastleStealer to steal browser and wallet credentials and a 32-bit path drops Remcos to enable keylogging, screen and webcam capture, and remote control.
  • Talos published indicators of compromise and mitigation advice that urge teams to avoid untrusted installers, harden download practices, monitor for unusual C2 traffic tied to hardware IDs, and apply the published IoCs to detect and contain infections.