Trojanized WebEx & Zoom Installers Deliver Russian RAT
Russian threat actor UAT-11795 is distributing convincing trojanized versions of popular enterprise software (WebEx, Zoom, MobaXterm, DBeaver) to deploy the Starland remote access trojan, exploiting users' inherent trust in well-known application brands. The attack succeeds primarily because end users cannot visually distinguish a malicious installer from a legitimate one when downloaded from unofficial or typosquatted sources. Once installed, Starland exfiltrates credentials, cryptocurrency wallets, and Active Directory data while establishing persistent C2 channels — including a novel Polygon blockchain-based fallback — making detection and remediation exceptionally difficult. This campaign illustrates that supply chain and software distribution integrity are now frontline security concerns, not just a developer responsibility.
Tactical Insight
Immediate actions
- Enforce a policy requiring all software downloads to originate exclusively from official vendor websites or a centrally managed internal software repository.
- Block execution of HTA files and restrict PowerShell execution policy to signed scripts only via Group Policy or endpoint management tools.
- Deploy or update endpoint detection and response (EDR) solutions with behavioral rules targeting NSIS installers dropping Python loaders and unauthorized PowerShell C2 activity.
Long-term improvements
- Implement application allowlisting so only cryptographically verified, pre-approved executables can run on corporate endpoints.
- Establish a formal software vetting and distribution process, including hash verification and digital signature validation before any installer is permitted in the environment.
- Segment networks so that workstations cannot directly reach cryptocurrency or blockchain endpoints, limiting the utility of novel C2 channels like Polygon smart contracts.
Detection measures
- Monitor and alert on anomalous outbound connections to blockchain RPC endpoints, unusual PowerShell parent-child process chains, and unexpected credential store access.
- Enable detailed logging of process creation, network connections, and file system changes (Windows Event IDs 4688, 4663, Sysmon) and forward to a SIEM for correlation.
- Conduct regular phishing and social engineering awareness training that specifically covers risks of downloading software outside approved channels.