HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Financially Motivated Campaign Deploys Novel Starland RAT and WLDR C2 Implant Across Multiple Software Vectors

Cisco Talos reports UAT‑11795 delivering a new Python‑based Starland RAT and a PowerShell WLDR C2 implant through trojanized installers of popular tools. The threat targets credentials and crypto wallets, underscoring the need for robust SOC 2 access‑control and security‑awareness evidence.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 blog.talosintelligence.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
blog.talosintelligence.com

Financially Motivated Campaign Deploys Novel Starland RAT and WLDR C2 Implant Across Multiple Software Vectors

What Happened — Cisco Talos uncovered UAT‑11795, a Russian‑speaking, financially motivated threat group that has been delivering a Python‑based “Starland RAT” and a PowerShell‑based “WLDR” memory implant since June 2025. The implants are dropped via trojanized installers of legitimate‑looking tools (e.g., MobaXterm, WebEx, Zoom, DBeaver, FACEIT) to steal credentials and cryptocurrency wallets.

Why It Matters for Compliance & Audit Readiness

  • The campaign exploits gaps in employee security awareness and credential‑handling policies – a direct test of SOC 2 CC6.1 (Logical Access Security) and CC6.2 (User Access Management).
  • Continuous evidence of security‑awareness training and endpoint monitoring can serve as audit‑ready proof that your organization mitigates social‑engineering‑driven malware.
  • Mapping this threat to your SOC 2 control framework highlights the need for documented, repeatable training programs and real‑time detection of anomalous PowerShell activity.

Who Is Affected – Technology & SaaS firms, financial services, and any organization whose users download remote‑admin, collaboration, or developer tools.

Recommended Actions

  • Refresh security‑awareness curricula to cover trojanized installers and RAT detection.
  • Deploy or tune EDR solutions to alert on unusual PowerShell memory implants and encrypted beaconing.
  • Enforce MFA and least‑privilege principles for all privileged accounts.

Source: Cisco Talos Blog

Technical Notes – The WLDR implant uses encrypted beaconing, task queuing, and a Runspace execution engine; Starland RAT is Python‑based. Delivery vectors include trojanized installers for MobaXterm, Cisco WebEx, Zoom, DBeaver, and FACEIT. No specific CVE is cited. Source: same as above

📰 Original Source
https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →