WLDR Agent is a bespoke PowerShell-based in-memory command-and-control implant associated with the financially motivated, Russian-speaking threat cluster UAT-11795. It is used as a follow-on payload in a broader Windows intrusion campaign focused on credential theft and cryptocurrency asset theft, with observed victim concentration in the United States and additional activity affecting parts of Europe.
The implant operates entirely in memory and functions as a backdoor for encrypted remote tasking. Its core features include encrypted HTTP or HTTPS beaconing, task queuing, reconnection logic, host reconnaissance, and a Runspace-based execution engine that can process commands in parallel using up to ten concurrent threads. Reported implementations use strong cryptographic protections for command-and-control traffic, including AES-256-CBC encryption, HMAC-SHA256 for integrity, and PBKDF2-SHA256-derived keys. WLDR Agent also uses a mutex guard to prevent duplicate execution on the same host.
WLDR Agent is deployed after initial compromise through a multi-stage infection chain that has been linked to ClickFix-style social engineering and trojanized software installers impersonating legitimate applications. In observed activity, Starland RAT serves as an earlier-stage implant and can execute an embedded PowerShell stager that decrypts and launches WLDR components in memory. The malware is designed for modular post-compromise operations, enabling operators to execute additional PowerShell commands or scripts and maintain covert access without relying on files written to disk.
The malware targets Windows systems and forms part of an intrusion set that also employs Starland RAT, CastleStealer, and Remcos RAT. Its role within the campaign is primarily covert remote access and post-exploitation task execution rather than broad self-propagation or destructive activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Starland RAT provides persistent remote access, cryptocurrency wallet enumeration, screenshot capture, and shellcode injection capabilities, while the WLDR Agent provides an encrypted, memory-resident beaconing capability with multi-threaded PowerShell execution.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence follows through a scheduled task and a startup shortcut.
At the operator discretion, Starland RAT deploys the WLDR Agent by executing an embedded PowerShell script...
At the operator discretion, Starland RAT deploys the WLDR Agent by executing an embedded PowerShell script... WLDR runs a PowerShell RunspacePool of up to ten concurrent threads...
This runs an embedded VBScript that drops a Windows batch file into the user profile’s application temporary folder
This runs an embedded VBScript that drops a Windows batch file into the user profile’s application temporary folder
The PowerShell stager is heavily obfuscated... The compiled Python loader is a relatively large file obfuscated with numerous junk functions... implementing XOR decryption
The installer drops a Python loader disguised as a LICENSE.txt file, which XOR-decrypts (key 0xC6) and reflectively executes Starland RAT entirely in memory...
Both are built to steal credentials, browser data, and cryptocurrency wallet assets
Two Telegram bots receive victim fingerprints and wallet inventories.
This telemetry is transmitted via HTTP POST with XOR and Base64 encoding to primary C2 domains, with polling every 50 to 60 seconds.
containing instructions to first download and implant a trojanized installer from the attacker-controlled staging domain onto the victim machine
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An in-memory PowerShell backdoor used in the campaign for encrypted beaconing and interactive, multi-threaded operator control of infected machines.
A bespoke PowerShell C2 memory implant deployed by Starland RAT that provides encrypted, memory-resident beaconing and parallelized command execution using a RunspacePool with up to ten concurrent threads.
A PowerShell-based in-memory command-and-control implant with encrypted beaconing, task queuing, and a Runspace execution engine to execute additional payloads; used to steal credentials, browser data, and cryptocurrency wallet assets while maintaining persistence.
A bespoke in-memory PowerShell remote access implant delivered through a WLDR stager/downloader chain. It uses encrypted HTTP/HTTPS C2 communications, host reconnaissance, mutex protection, reconnect logic, and a RunspacePool-based task execution engine for interactive remote PowerShell execution and modular payload delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.