INTEL_REPORT
Cisco Talos Blog · published 7/16/2026, 10:00:01 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting user…
https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign
sha256:609565bd1236f14a5b4df9fe2c1093a2a77d5ac39339767336a54d24d525e92d
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| kernel32.dll |
| Open → |
| domain | amsi.dll | Open → |
| domain | any.run | Open → |
| domain | eorthopaedics.com | Open → |
| domain | web-devtools.com | Open → |
| domain | zynaris.io | Open → |
| domain | sastoro.com | Open → |
| domain | windowscreenrepairnearme.com | Open → |
| domain | aipythondevs.com | Open → |
| domain | zone.identifier | Open → |
| domain | polygon-rpc.com | Open → |
| domain | api64.ipify.org | Open → |
| domain | txt.downloader.agent | Open → |
| domain | html.downloader.agent | Open → |
| domain | py.loader.agent | Open → |
| domain | ps1.trojan.agent | Open → |
| domain | ps1.trojan.wldragent | Open → |
| domain | ps1.downloader.agent | Open → |
| domain | win.trojan.castlestealer | Open → |
| domain | win.trojan | Open → |
| domain | win.malware.starland | Open → |
| domain | win.malware.remka | Open → |