<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-kv7oahrsr" -->

---
title: Russian hackers trojanize WebEx, Zoom apps to push...
description: A financially motivated Russian threat actor (UAT-11795) is distributing trojanized installers for popular software including WebEx, Zoom, MobaXterm, DBeaver,...
canonical: https://daily.dev/posts/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-kv7oahrsr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Russian hackers trojanize WebEx, Zoom apps to push Starland malware | daily.dev
og:description: A financially motivated Russian threat actor (UAT-11795) is distributing trojanized installers for popular software including WebEx, Zoom, MobaXterm, DBeaver,...
og:url: https://daily.dev/posts/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-kv7oahrsr
og:image: https://api.daily.dev/og/posts/KV7OAHrSR.png
og:image:alt: Russian hackers trojanize WebEx, Zoom apps to push Starland malware
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Russian hackers trojanize WebEx, Zoom apps to push Starland malware

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

A financially motivated Russian threat actor (UAT-11795) is distributing trojanized installers for popular software including WebEx, Zoom, MobaXterm, DBeaver, and FaceIT to deploy a new backdoor called Starland RAT. Active since at least June 2025, the campaign primarily targets U.S. users. The attack chain begins with an HTA file delivering a trojanized NSIS installer containing a Python loader, which establishes persistence via Windows Registry and loads Starland RAT. The RAT collects browser credentials, cryptocurrency wallet data, Active Directory info, and system details, while also deploying secondary payloads: CastleStealer (info-stealer) and Remcos RAT. A novel PowerShell C2 framework called WLDR is used, featuring encrypted beaconing and hardware-bound payload delivery. C2 communication includes a blockchain-based fallback mechanism using a Polygon smart contract.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware>

## Similar posts on daily.dev

- [SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in ValleyRAT Campaign](https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7) · Security Boulevard · 0 upvotes · 0 comments
- [This stealthy Windows RAT holds live conversations with its operators](https://daily.dev/posts/this-stealthy-windows-rat-holds-live-conversations-with-its-operators-5bhtgzqlt) · CSO Online · 0 upvotes · 0 comments
- [JDownloader site hacked to replace installers with Python RAT malware](https://daily.dev/posts/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware-zf16t1da8) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-kv7oahrsr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Russian hackers trojanize WebEx, Zoom apps to push Starland malware","url":"https://daily.dev/posts/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-kv7oahrsr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-kv7oahrsr"},"datePublished":"2026-07-17T00:17:30.399Z","dateModified":"2026-07-17T00:17:54.120Z","description":"A financially motivated Russian threat actor (UAT-11795) is distributing trojanized installers for popular software including WebEx, Zoom, MobaXterm, DBeaver,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b6e2a3f9c48284314b9bab423955e174?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b6e2a3f9c48284314b9bab423955e174?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-kv7oahrsr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,malware","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Russian hackers trojanize WebEx, Zoom apps to push Starland malware"}]}
```

