Overview
- Cisco Talos published a detailed analysis on July 16 attributing the campaign to a financially motivated Russian-speaking group tracked as UAT-11795 and naming the primary backdoor Starland RAT.
- Initial compromise begins with an HTA that fetches a trojanized NSIS installer; that installer runs a Python loader disguised as LICENSE.txt which establishes persistence and decrypts Starland.
- Starland performs sandbox checks, creates scheduled tasks and Startup shortcuts for persistence, enumerates system and Active Directory details, and searches for browser data and more than 40 desktop and extension cryptocurrency wallets.
- After initial execution the actor delivers secondary tools: a 64-bit path drops CastleStealer to steal browser and wallet credentials and a 32-bit path drops Remcos to enable keylogging, screen and webcam capture, and remote control.
- Talos published indicators of compromise and mitigation advice that urge teams to avoid untrusted installers, harden download practices, monitor for unusual C2 traffic tied to hardware IDs, and apply the published IoCs to detect and contain infections.