Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework

7a22441a6d6a5a77df8cdbfd39ca694c627298f8

TLP:CLEAR
Active

SHA-1 Hash

Description

A Russian-speaking, financially motivated threat actor designated UAT-11795 has been conducting a sophisticated malware campaign since June 2025, primarily targeting users in the United States. The operation utilizes ClickFix-style social engineering techniques with trojanized software installers for applications like MobaXterm, Cisco WebEx, Zoom, DBeaver, and FACEIT. The campaign deploys Starland RAT, a custom Python-based remote access tool that establishes persistence, performs reconnaissance, and collects cryptocurrency wallet information. The malware employs blockchain-based fallback C2 mechanisms via Polygon smart contracts. Additionally, the operation deploys the previously undocumented WLDR PowerShell framework, CastleStealer, and Remcos RAT, demonstrating a modular architecture focused on credential theft, cryptocurrency harvesting, and long-term post-compromise access.

Sightings (0)

No sightings recorded yet

Details

Name / Label
ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework
Pattern Type
STIX
Confidence
75%
Valid From
Aug 4, 2026 18:00
Total Sightings
0
Added
Aug 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 7a22441a6d6a5a77df8cdbfd39ca694c627298f8

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.