Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors uat-11795

Also known as: Europe, tracked as, according to IT Pro, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

UAT‑11795 demonstrates a high level of sophistication for a financially driven actor. It routinely deploys the Starland RAT through trojanized software installers, delivering additional custom PowerShell and Python payloads that enable persistence via cloud or container images. The threat group complements its RAT portfolio with CastleStealer and Remcos RAT, often leveraging compromised third‑party servers—particularly in web services and serverless environments—for both C2 communication and exfiltration. The actor’s engineering capabilities extend to building bespoke malware modules: droppers, packers, post‑compromise tools, backdoors, and self‑signed certificates that obscure malicious content. This suite of tools allows UAT‑11795 to perform account discovery, credential theft, process injection, and data encryption for impact, culminating in ransomware blasts, business email compromise (BEC), and cryptocurrency thefts aimed at generating financial gains. UAT‑11795’s operational style relies heavily on internal spearphishing via compromised accounts, enabling lateral movement within target enterprises. The group also exploits advanced cloud platforms—including Cloudflare Workers and AWS Lambda—to evade detection by embedding malicious code into legitimate traffic or hosting botnet infrastructure hidden behind trusted providers. Overall, the actor exhibits a complex, multi‑phase campaign that combines initial access through both spearphishing and serverless exploitation with stealthy persistence mechanisms and financially motivated exfiltration. Its use of custom scripts and proprietary C2 frameworks indicates an in‑house development capability, reinforcing its adaptability across target sectors.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Media
Government
Utilities
Gaming
Manufacturing
Information technology

Targeted Countries / Regions

United States of America
Germany
Romania
Venezuela, Bolivarian Republic of
US
CN
GB
DE
RO

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

UAT‑11795 is a Russian‑speaking, financially motivated threat actor that employs a combination of trojanized installers and custom PowerShell/Python payloads to deliver Starland RAT, CastleStealer, Remcos RAT, and its own WLDR C2 framework. The group exploits compromised third‑party services and serverless cloud functions to conceal command‑and‑control traffic while building botnets and conducting spearphishing campaigns across financial services, defense, government, utilities, and media organizations worldwide.

Goals & Targeting

UAT‑11795’s strategic objectives center on maximizing financial gain through ransomware deployment, BEC, and cryptocurrency theft. Targeting is deliberately broad yet focused: the actor selects organizations within finance, defense, government, utilities, media, gaming, manufacturing, and IT that possess valuable data or high-value assets. Geographic focus spans North America (U.S., Canada), Europe (Germany, United Kingdom, Romania), and Latin America (Venezuela, Bolivia), with evidence of attacks on U.S. federal agencies and European financial institutions. The actor employs multi‑stage lateral movement—initial phishing, exploitation of compromised cloud infrastructure, internal impersonation—to expand reach within victim networks.

Enhanced Description

Key Capabilities

  • Deploys Starland RAT via trojanized installers
  • Delivers custom Python and PowerShell payloads
  • Uses CastleStealer and Remcos RAT as alternative implants
  • Builds or hijacks botnets by compromising third‑party systems
  • Exploits serverless cloud functions for covert operations
  • Injects malicious content into online network traffic for initial access
  • Leverages compromised web services for C2 and exfiltration
  • Develops custom malware including payloads, droppers, post‑compromise tools, backdoors, and packers
  • Creates or modifies system processes to maintain control
  • Implants malicious cloud/container images for persistence
  • Uses internal spearphishing via impersonation to expand reach
  • Performs financial theft through ransomware, BEC, and cryptocurrency exploitation

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. attack.mitre.org — Cited by web research for: Interception
  3. blog.talosintelligence.com — Cited by web research for: Telegram
  4. redcanary.com — Cited by web research for: SocGholish
  5. blog.talosintelligence.com — Cited by web research for: PsExec

Intel Summary

40

Techniques

43

Tools

0

Campaigns

52

IOCs

0

Observed Data

12

Tactics

Tags

Ransomware
APT
Zero-Day Exploitation
Vulnerability Management
Patch Cycle
Cybersecurity Infrastructure

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
Jul 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.