Also known as: Europe, tracked as, according to IT Pro, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
UAT‑11795 demonstrates a high level of sophistication for a financially driven actor. It routinely deploys the Starland RAT through trojanized software installers, delivering additional custom PowerShell and Python payloads that enable persistence via cloud or container images. The threat group complements its RAT portfolio with CastleStealer and Remcos RAT, often leveraging compromised third‑party servers—particularly in web services and serverless environments—for both C2 communication and exfiltration. The actor’s engineering capabilities extend to building bespoke malware modules: droppers, packers, post‑compromise tools, backdoors, and self‑signed certificates that obscure malicious content. This suite of tools allows UAT‑11795 to perform account discovery, credential theft, process injection, and data encryption for impact, culminating in ransomware blasts, business email compromise (BEC), and cryptocurrency thefts aimed at generating financial gains. UAT‑11795’s operational style relies heavily on internal spearphishing via compromised accounts, enabling lateral movement within target enterprises. The group also exploits advanced cloud platforms—including Cloudflare Workers and AWS Lambda—to evade detection by embedding malicious code into legitimate traffic or hosting botnet infrastructure hidden behind trusted providers. Overall, the actor exhibits a complex, multi‑phase campaign that combines initial access through both spearphishing and serverless exploitation with stealthy persistence mechanisms and financially motivated exfiltration. Its use of custom scripts and proprietary C2 frameworks indicates an in‑house development capability, reinforcing its adaptability across target sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT‑11795 is a Russian‑speaking, financially motivated threat actor that employs a combination of trojanized installers and custom PowerShell/Python payloads to deliver Starland RAT, CastleStealer, Remcos RAT, and its own WLDR C2 framework. The group exploits compromised third‑party services and serverless cloud functions to conceal command‑and‑control traffic while building botnets and conducting spearphishing campaigns across financial services, defense, government, utilities, and media organizations worldwide.
Goals & Targeting
UAT‑11795’s strategic objectives center on maximizing financial gain through ransomware deployment, BEC, and cryptocurrency theft. Targeting is deliberately broad yet focused: the actor selects organizations within finance, defense, government, utilities, media, gaming, manufacturing, and IT that possess valuable data or high-value assets. Geographic focus spans North America (U.S., Canada), Europe (Germany, United Kingdom, Romania), and Latin America (Venezuela, Bolivia), with evidence of attacks on U.S. federal agencies and European financial institutions. The actor employs multi‑stage lateral movement—initial phishing, exploitation of compromised cloud infrastructure, internal impersonation—to expand reach within victim networks.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
40
Techniques
43
Tools
0
Campaigns
52
IOCs
0
Observed Data
12
Tactics