UAT-11795 is a Russian-speaking, financially motivated threat actor active since at least June 2025. The actor has conducted malware campaigns primarily against users in the United States, with additional victims observed in Germany, Romania, Venezuela, and elsewhere in Europe. Activity indicates a strong focus on credential theft and cryptocurrency theft rather than destructive or espionage objectives. UAT-11795 is associated with a multi-stage intrusion chain that relies on social engineering and trojanized installers for legitimate software to gain initial access. Reporting links the activity to ClickFix-style lures and weaponized HTA execution, followed by delivery of NSIS-based installers that continue normal software installation to reduce suspicion while covertly launching malware. The actor’s tooling includes Starland RAT, a Python-based remote access trojan, and WLDR, a bespoke PowerShell memory-resident command-and-control implant. Additional payloads observed in the actor’s operations include CastleStealer and Remcos RAT. Starland RAT is used for host reconnaissance, credential theft, cryptocurrency wallet discovery, screenshot capture, persistence, remote command execution, and follow-on payload delivery. It performs anti-analysis checks against common sandbox artifacts, inventories system and Active Directory context, and can inject shellcode for both 32-bit and 64-bit execution paths. Persistence has been established through scheduled tasks and startup shortcuts, and some stages also used logon-triggered autorun mechanisms. The malware communicates with command-and-control infrastructure using encrypted or encoded traffic and includes a resilient fallback mechanism that retrieves alternate command-and-control information from a Polygon smart contract. WLDR provides in-memory post-exploitation capability through encrypted beaconing, modular tasking, and concurrent PowerShell runspace execution. It is designed for long-term access and flexible remote operations without writing its core implant to disk. Supporting loaders used in the campaign dynamically resolve APIs, decrypt payloads in memory, and bypass defensive telemetry such as AMSI and ETW before reflective or runspace-based execution. Operationally, UAT-11795 appears opportunistic and volume-driven, using trusted software themes to reach a broad victim pool while prioritizing systems likely to yield browser credentials, wallet data, and other monetizable access. The actor has also used Telegram-based notification or management mechanisms as part of campaign operations. No widely used public alias beyond UAT-11795 is established in the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
54 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated malware campaign using ClickFix-style social engineering, trojanized software installers, and Starland RAT to gain persistence and deploy WLDR, CastleStealer, and Remcos RAT, with emphasis on credential theft, cryptocurrency wallet harvesting, and long-term access.
Financially motivated credential theft and cryptocurrency theft campaign using trojanized software installers to deliver Starland RAT to Windows users.
Financially motivated campaign using ClickFix lures and trojanized installers to deliver Starland RAT and WLDR Agent for persistent remote access, credential theft, and cryptocurrency wallet theft.
A Russian-speaking threat actor conducting credential theft and cryptocurrency theft campaigns using trojanized installers for legitimate software, social engineering, and custom malware to establish persistence and exfiltrate browser, credential, and wallet data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.