[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fa9rz-xPjyRB24jmJoqBqz2Sawn9jBdSNWgUClgmMTAs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"35f1e5f6-afeb-43d2-aaec-475b73254cb6","trojanized-webex-zoom-installers-deliver-russian-rat","c7b8d12a-ac2e-4f2b-a448-1d061bfa8c7b","Trojanized WebEx & Zoom Installers Deliver Russian RAT","Russian threat actor UAT-11795 is distributing convincing trojanized versions of popular enterprise software (WebEx, Zoom, MobaXterm, DBeaver) to deploy the Starland remote access trojan, exploiting users' inherent trust in well-known application brands. The attack succeeds primarily because end users cannot visually distinguish a malicious installer from a legitimate one when downloaded from unofficial or typosquatted sources. Once installed, Starland exfiltrates credentials, cryptocurrency wallets, and Active Directory data while establishing persistent C2 channels — including a novel Polygon blockchain-based fallback — making detection and remediation exceptionally difficult. This campaign illustrates that supply chain and software distribution integrity are now frontline security concerns, not just a developer responsibility.","**Immediate actions:**\n- Enforce a policy requiring all software downloads to originate exclusively from official vendor websites or a centrally managed internal software repository.\n- Block execution of HTA files and restrict PowerShell execution policy to signed scripts only via Group Policy or endpoint management tools.\n- Deploy or update endpoint detection and response (EDR) solutions with behavioral rules targeting NSIS installers dropping Python loaders and unauthorized PowerShell C2 activity.\n\n**Long-term improvements:**\n- Implement application allowlisting so only cryptographically verified, pre-approved executables can run on corporate endpoints.\n- Establish a formal software vetting and distribution process, including hash verification and digital signature validation before any installer is permitted in the environment.\n- Segment networks so that workstations cannot directly reach cryptocurrency or blockchain endpoints, limiting the utility of novel C2 channels like Polygon smart contracts.\n\n**Detection measures:**\n- Monitor and alert on anomalous outbound connections to blockchain RPC endpoints, unusual PowerShell parent-child process chains, and unexpected credential store access.\n- Enable detailed logging of process creation, network connections, and file system changes (Windows Event IDs 4688, 4663, Sysmon) and forward to a SIEM for correlation.\n- Conduct regular phishing and social engineering awareness training that specifically covers risks of downloading software outside approved channels.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 9: Email and Web Browser Protections","CIS Control 13: Network Monitoring and Defense","NIST SP 800-161: Supply Chain Risk Management","NIST CSF DE.CM-1: Network Monitoring","NIST AC-3: Access Enforcement","NIST SI-3: Malicious Code Protection","NIST SR-4: Provenance of Software and Components","MITRE ATT&CK T1195.002: Compromise Software Supply Chain","MITRE ATT&CK T1059.001: PowerShell Execution","MITRE ATT&CK T1568: Dynamic Resolution (Blockchain C2)","ITIL: Change and Release Management","GDPR Article 32: Security of Processing (credential & personal data exfiltration risk)","published","2026-07-16T12:21:53.066358+00:00","2026-07-16T12:21:52.97+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Frussian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware\u002F","russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-0bb78f","Russian hackers trojanize WebEx, Zoom apps to push Starland malware",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":41,"name":42,"slug":43,"description":44,"color":45},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":47,"name":48,"slug":49,"description":50,"color":51},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[53],{"id":54,"date":55,"edition":56,"title":57,"audio_url":58},"e96741f5-df55-47e4-92a2-0356c9b000ac","2026-07-16","afternoon","ThreatNoir Afternoon Brief — July 16","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-16\u002Fthreatnoir-afternoon-brief-2026-07-16.mp3"]