Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Trusted Meeting Apps Become the Bait in a Multi-Layer Windows Malware Campaign

Trusted Meeting Apps Become the Bait in a Multi-Layer Windows Malware Campaign
Photo by cottonbro studio on Pexels

A financially motivated Russian threat group is distributing modified installers that impersonate widely used applications such as WebEx, Zoom, MobaXterm, DBeaver, and FaceIT. The campaign deploys Starland RAT and additional malware capable of stealing credentials, cryptocurrency assets, messaging sessions, and Active Directory information.

News Date: 2026-07-16

Cybercriminals are exploiting confidence in familiar business software by distributing trojanized installers for popular communication and administration tools. The operation, attributed to a financially motivated Russian threat actor tracked as UAT-11795, has primarily targeted users in the United States, with additional victims observed in Germany, Romania, and Venezuela.

A Layered Windows Infection Chain

The malicious packages imitate legitimate installers for WebEx, Zoom, MobaXterm, DBeaver, and FaceIT. Researchers have not confirmed exactly how victims reach the files, although the campaign may use ClickFix-style social engineering that persuades users to execute commands or installation steps presented as technical repairs.

Once launched, the chain uses an HTA file and a modified NSIS installer containing a Python loader disguised as a license document. The loader changes the Windows Registry for persistence before decrypting and starting Starland RAT. The malware can create scheduled tasks, place components in the Startup folder, assess whether it is running inside a security sandbox, and attempt to obtain higher privileges.

Credentials and Cryptocurrency Are Prime Targets

Starland RAT collects browser information, system details, Active Directory data, screenshots, and cryptocurrency assets associated with more than 40 desktop and browser-extension wallets. It can also execute commands, inject shellcode, and retrieve additional payloads. Observed infections delivered CastleStealer on 64-bit systems and Remcos RAT through a separate 32-bit chain.

The command infrastructure includes a notable resilience feature. If the primary server cannot be reached, the malware can query a Polygon blockchain smart contract for an encrypted fallback domain. The attackers also use an in-memory PowerShell command framework called WLDR, making conventional file-based detection less dependable.

What Organizations Should Do

  • Restrict software installation to approved vendor portals and managed deployment services.
  • Monitor HTA execution, suspicious PowerShell activity, new scheduled tasks, and unexpected Startup folder changes.
  • Use application control to block unapproved installers and script interpreters.
  • Review browser, cryptocurrency, messaging, and domain credentials after a suspected infection.

In my view, the most important lesson is that a recognizable application name is no longer a meaningful trust signal. Organizations need to verify the origin, signature, and hash of software before execution, while reducing the ability of ordinary users to install unmanaged packages.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path