news.mlab.sh
Back to the feed
threat-intel

Begun, the Patch Wars have

High
Summary

Cisco Talos has identified a sophisticated, financially motivated Russian-speaking adversary, UAT-11795, actively targeting users in the U.S. and Europe since June 2025. This campaign utilizes trojanized software installers – including popular tools like Webex, Zoom, and MobaXterm – to deliver a custom Python-based remote access tool called "Starland RAT." The attackers employ evasive techniques, including AMSI and ETW bypasses, and a blockchain-anchored fallback mechanism to maintain persistent command and control. Once inside, they deploy secondary payloads like CastleStealer and Remcos RAT to steal credentials and cryptocurrency assets. This campaign highlights a significant increase in vulnerability patching demands and underscores the ongoing threat landscape, particularly concerning supply-chain attacks and advanced persistent threats.

This week’s Patch Tuesday saw Microsoft issue a record 622 vulnerabilities, more than triple the previous high of around 200. This surge in vulnerabilities is largely attributed to Microsoft’s AI frontier-accelerated research, which has led to a faster identification and disclosure of security flaws. However, the sheer volume of patches presents a significant challenge for organizations, particularly smaller companies with limited resources. While Microsoft has the capacity to address these issues, many other vendors will face a longer timeline for patching.

Cisco Talos is currently tracking a campaign by UAT-11795, a financially motivated Russian-speaking adversary. This group leverages trojanized software installers – including popular tools like Webex, Zoom, and MobaXterm – to deliver a custom Python-based remote access tool known as "Starland RAT." The attackers use highly evasive techniques, including AMSI and ETW bypasses, and a clever blockchain-anchored fallback mechanism to maintain persistent command and control. Once inside, they rapidly deploy secondary payloads like CastleStealer and Remcos RAT to siphon high-value credentials and cryptocurrency assets.

This opportunistic campaign casts a wide net across multiple victim profiles, turning a simple software download into a full-blown compromise. The UAT-11795 group employs advanced tactics to avoid detection, making it a persistent and evolving threat. The volume of vulnerabilities and the complexity of the attacks necessitate a robust and proactive approach to security.

To mitigate these risks, users should be educated on ClickFix social engineering tactics and warned against downloading software from unofficial sources. Monitoring for suspicious execution of mshta.exe and unusual PowerShell activity, particularly scripts executing from memory or creating unexpected scheduled tasks, is crucial. Endpoint detection solutions should be tuned to catch in-memory execution and AMSI tampering.

Top security headlines this week include:

  • Microsoft patches record 622 flaws, including two zero-days under active attack (The Hacker News)
  • RabbitMQ vulnerability threatens enterprise systems (SecurityWeek)
  • Nigeria deepens cybersecurity efforts as cybercriminals see more profits (DarkReading)
  • Two-click cursor exploit enables dev environment takeover (DarkReading)

Talos is providing further insights through:

  • [Video] Where protection starts: Cisco Talos Intelligence Integrations
  • The Hunter’s Paradox: Is it time to embrace automated threat hunting?
  • The serpent’s tongue: Luring the Python out of its den
  • ARToken: How attackers are bypassing MFA and maintaining access
  • Upcoming events where you can find Talos - Black Hat USA (Aug 1-6) Las Vegas, NV and DEF CON 34 (Aug 6-9) Las Vegas, NV

Most prevalent malware files from Talos telemetry over the past week:

  • SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
  • MD5: 2915b3f8b703eb744fc54c81f4a9c67f
  • SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
  • MD5: 38de5b2dcacba6dccc175b6ce1b7ed0a
  • SHA256: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a
  • MD5: 0398df5a18f71efcfeef4571a2cef577
Read the full article at Cisco Talos