Skip to main content

AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign

3 min read Runtime Rebel Intel
Primary source: blog.talosintelligence.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Organizations face an unprecedented patching workload driven by AI-accelerated vulnerability research and active campaigns by the UAT-11795 threat group.
  • Systems relying on Microsoft products facing record patch volumes and users downloading trojanized installers like Webex and Zoom are directly affected.
  • Prioritize critical zero-day patches, monitor for in-memory PowerShell execution, and educate users against unofficial software downloads and ClickFix tactics.

Advertisement

Overview of the Patch Volume Surge

The threat landscape has reached a significant inflection point as artificial intelligence frontier models accelerate vulnerability discovery and research. According to Cisco Talos, a recent Patch Tuesday shattered historical records by addressing 622 vulnerabilities in a single month—surpassing the total number of patches issued across the entire year of 2018. Out of this massive volume, 62 flaws are rated critical, including three zero-days, with two confirmed to be under active exploitation in the wild.

This explosive growth in vulnerability disclosures introduces severe friction for enterprise change management and IT administrators. Traditional testing and deployment workflows struggle to keep pace when faced with such high-volume telemetry. As vendors increasingly leverage automated tooling to unearth flaws, organizations must adapt to a permanent elevation in patch cadence and threat notification volume.

UAT-11795 and Starland RAT Campaign Analysis

Concurrent with the flood of software patches, Cisco Talos has detailed an ongoing campaign by a financially motivated, Russian-speaking threat actor tracked as UAT-11795. Active since at least June 2025, this adversary targets enterprise users across the United States and Europe using sophisticated delivery mechanisms.

Infection Vectors and Tooling

  • Trojanized Installers: The attackers compromise popular productivity and utility tools, including Webex, Zoom, and MobaXterm, embedding malicious payloads inside seemingly legitimate software packages.
  • Starland RAT: Initial execution deploys a custom Python-based remote access tool that functions as a staging platform for secondary payloads.
  • WLDR Agent: A bespoke, in-memory PowerShell command-and-control implant designed to evade traditional signature-based detection.
  • Secondary Payloads: Once persistence is established, the operators deploy tools like CastleStealer and Remcos RAT to harvest high-value credentials and cryptocurrency assets.

To maintain operational resilience, UAT-11795 utilizes advanced evasion techniques, including Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) bypasses, alongside a blockchain-anchored fallback mechanism for command-and-control communication.

Defensive Recommendations and Mitigations

Defenders operating under the strain of record patch loads and sophisticated threat actor campaigns must prioritize structural resilience and visibility:

  • Tune Endpoint Detection: Ensure security tooling is explicitly configured to detect in-memory execution, AMSI tampering, and unusual PowerShell scripts running from memory or creating unexpected scheduled tasks.
  • Monitor Suspicious Processes: Keep a close watch on the execution of native binaries like mshta.exe and investigate abnormal network connections tied to administrative software.
  • User Awareness Training: Educate personnel on the risks of unofficial software downloads and emerging social engineering strategies such as ClickFix tactics.
  • Streamline Patch Management: Re-evaluate change management queues to rapidly ingest and deploy critical updates, prioritizing zero-days and actively exploited flaws over routine maintenance.

Related: Cisco Talos Previews AI Threats and Warlock Ransomware at Black Hat, OpenAI Model Sandbox Escape Highlights Emerging AI Security Risks

Advertisement

Advertisement