Starland RAT is a Python-based remote access trojan used by the financially motivated, Russian-speaking threat actor UAT-11795 in campaigns active since at least June 2025. It has been observed primarily against Windows users in the United States, with additional victimology in Europe and Venezuela, and appears particularly focused on credential theft and cryptocurrency wallet theft.
The malware is delivered through social-engineering-driven infection chains that use ClickFix-style lures and trojanized installers masquerading as legitimate software. In observed intrusions, a staged loader chain executes Starland RAT directly in memory, helping reduce on-disk exposure while preserving the appearance of a normal software installation.
Once active, Starland RAT performs anti-analysis checks against common sandbox usernames and hostnames, gathers host reconnaissance, and inventories security and domain context. Reported collection includes hardware and operating system details, installed antivirus products, Active Directory membership and privilege context, screenshots, browser-related data, and the presence of more than 40 cryptocurrency wallet applications and browser extensions. The malware exfiltrates collected victim information to command-and-control infrastructure using encoded and encrypted communications.
Starland RAT establishes persistence through scheduled tasks and Startup-folder shortcuts, and some reporting also indicates attempts to elevate privileges. It supports remote shell command execution, delivery of additional payloads, and injection or execution of both 32-bit and 64-bit shellcode, making it suitable as both an access tool and a staging platform for follow-on malware. Observed secondary payloads associated with Starland RAT activity include CastleStealer, Remcos RAT, and the bespoke WLDR PowerShell memory implant.
A notable resilience feature is its fallback command-and-control discovery mechanism, which retrieves backup infrastructure information from a Polygon smart contract when primary infrastructure is unavailable. This, combined with in-memory execution, anti-analysis logic, and modular payload delivery, makes Starland RAT a flexible intrusion platform for long-term access, credential theft, cryptocurrency targeting, and broader post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The operation employs suspected ClickFix-style social engineering, trojanized software installers, and a custom Python-based remote access tool, Starland RAT, to establish persistent access and deploy additional malware, including the previously undocumented WLDR PowerShell framework, CastleStealer, and Remcos RAT.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The RAT establishes persistence using scheduled tasks and Startup folder shortcuts while performing anti-analysis checks against common sandbox usernames and hostnames before initiating malicious activity.
Persistence is established through a randomized scheduled task named PythonLauncher followed by three characters with an AtLogOn trigger...
After registration, the RAT polls its C2 server approximately every 50 to 60 seconds and supports execution of shell commands, process injection of both 32-bit and 64-bit shellcode, and delivery of additional executable payloads.
At the operator discretion, Starland RAT deploys the WLDR Agent by executing an embedded PowerShell script... WLDR runs a PowerShell RunspacePool of up to ten concurrent threads...
It can run shell commands, inject 32-bit or 64-bit shellcode, or download more files.
According to Talos, the actor “delivers a Python-based remote access tool” that runs in memory.
The RAT establishes persistence using scheduled tasks and Startup folder shortcuts while performing anti-analysis checks against common sandbox usernames and hostnames before initiating malicious activity.
Persistence is established through a randomized scheduled task named PythonLauncher followed by three characters with an AtLogOn trigger...
The RAT establishes persistence using scheduled tasks and Startup folder shortcuts while performing anti-analysis checks against common sandbox usernames and hostnames before initiating malicious activity.
Persistence is established through a randomized scheduled task named PythonLauncher followed by three characters with an AtLogOn trigger...
After registration, the RAT polls its C2 server approximately every 50 to 60 seconds and supports execution of shell commands, process injection of both 32-bit and 64-bit shellcode, and delivery of additional executable payloads.
The campaign uses ClickFix social engineering and trojanized software installers mimicking popular tools such as MobaXterm, WebEx, Zoom, and DBeaverCommunity to deliver a multi-stage infection chain.
After registration, the RAT polls its C2 server approximately every 50 to 60 seconds and supports execution of shell commands, process injection of both 32-bit and 64-bit shellcode, and delivery of additional executable payloads.
Delivered through an obfuscated PowerShell stager, WLDR operates entirely in memory... WLDR provides operators with an interactive PowerShell-based post-exploitation framework capable of executing additional scripts entirely in memory.
The installer drops a Python loader disguised as a LICENSE.txt file, which XOR-decrypts (key 0xC6) and reflectively executes Starland RAT entirely in memory...
The infection chain begins when a victim is directed via ClickFix lures to execute a command that downloads and launches a weaponized HTA file through mshta.exe.
The RAT establishes persistence using scheduled tasks and Startup folder shortcuts while performing anti-analysis checks against common sandbox usernames and hostnames before initiating malicious activity.
Starland RAT performs extensive host reconnaissance, collecting hardware identifiers, operating system details, Active Directory information, installed antivirus products, desktop screenshots, and the presence of more than 40 cryptocurrency wallet applications and browser extensions.
Starland RAT performs extensive host reconnaissance, collecting hardware identifiers, operating system details, Active Directory information, installed antivirus products, desktop screenshots, and the presence of more than 40 cryptocurrency wallet applications and browser extensions.
Starland RAT performs extensive host reconnaissance, collecting hardware identifiers, operating system details, Active Directory information, installed antivirus products, desktop screenshots, and the presence of more than 40 cryptocurrency wallet applications and browser extensions.
It then collects extensive host reconnaissance including ... Active Directory membership and domain privilege status...
Starland RAT performs extensive host reconnaissance, collecting hardware identifiers, operating system details, Active Directory information, installed antivirus products, desktop screenshots, and the presence of more than 40 cryptocurrency wallet applications and browser extensions.
If the primary C2 infrastructure becomes unavailable, the malware retrieves a fallback domain from a Polygon blockchain smart contract, providing a resilient fallback communication mechanism.
Two Telegram bots receive victim fingerprints and wallet inventories.
This telemetry is transmitted via HTTP POST with XOR and Base64 encoding to primary C2 domains, with polling every 50 to 60 seconds.
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom Python-based remote access trojan used to establish persistence, perform anti-analysis checks, conduct host reconnaissance, harvest cryptocurrency wallet and browser-related data, communicate with C2 infrastructure including blockchain-based fallback discovery, execute shell commands, inject shellcode, and deliver additional payloads.
A Python-based remote access trojan delivered via trojanized installers for trusted software. It runs in memory, steals browser credentials, screenshots, host profiling data, and inventories more than 40 cryptocurrency wallets. It also enables shell command execution, shellcode injection, and downloading of additional payloads.
A novel Python-based remote access trojan that provides persistent remote access, cryptocurrency wallet enumeration, screenshot capture, shellcode injection, host reconnaissance, sandbox evasion, and resilient C2 via primary domains with a Polygon smart-contract-based fallback.
A Python-based remote access trojan used to exfiltrate credentials, browser data, and cryptocurrency wallet assets while establishing persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.