← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 16, 2026 · 10:00via Cisco Talos

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Brief

  • Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
  • Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.”
  • The WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads.
  • UAT-11795 also has CastleStealer and Remcos RAT as alternative payload implants in their arsenal.
Read more on Cisco Talos