Skip to content

Trojans in WebEx and Zoom: Russian Attackers Distribute Starland RAT

The point: Russian attackers compromise popular video conferencing tools through trojans and use embedded Starland RAT to steal credentials and cryptocurrencies.

The threat group UAT-11795 manipulates WebEx and Zoom installers with trojanized software and deploys a new backdoor called Starland RAT to exfiltrate access credentials and cryptocurrencies.

The threat group UAT-11795, which seeks financial gain, has developed a new backdoor named Starland RAT and deploys it to compromise systems. The attackers leverage trojanized versions of popular video conferencing applications such as WebEx and Zoom as infection vectors.

By injecting manipulated installers of these popular tools, the attackers achieve high acceptance rates among victims. The installed Starland RAT enables the attackers to execute remote access on affected systems, spy on access credentials, and steal cryptocurrency holdings.

This approach demonstrates a further escalation in leveraging known, trusted software as a trojanization vector. It underscores the necessity to closely monitor and validate software distribution and update sources, as well as strengthen endpoint security through intrusion detection systems and threat monitoring.


Source: www.bleepingcomputer.com · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: