# AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign

> Analysis of a record Patch Tuesday driven by AI vulnerability research, alongside Cisco Talos findings on UAT-11795 deploying Starland RAT.

- Published: 2026-08-08T08:31:29.000Z
- Severity: high
- Category: Threat Intel
- Tags: Threat Intel, Zero-Day, Ransomware, Remcos, Python
- Author: Runtime Rebel Intel
- Primary source: https://blog.talosintelligence.com/begun-the-patch-wars-have/
- Canonical: https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign

## Key points

- Organizations face an unprecedented patching workload driven by AI-accelerated vulnerability research and active campaigns by the UAT-11795 threat group.
- Systems relying on Microsoft products facing record patch volumes and users downloading trojanized installers like Webex and Zoom are directly affected.
- Prioritize critical zero-day patches, monitor for in-memory PowerShell execution, and educate users against unofficial software downloads and ClickFix tactics.

## Overview of the [Patch](/glossary#patch) Volume Surge

The [threat landscape](/glossary#threat-landscape) has reached a significant inflection point as artificial intelligence frontier models accelerate [vulnerability](/glossary#vulnerability) discovery and research. According to [Cisco Talos](https://blog.talosintelligence.com/begun-the-patch-wars-have/), a recent [Patch Tuesday](/glossary#patch-tuesday) shattered historical records by addressing 622 vulnerabilities in a single month—surpassing the total number of patches issued across the entire year of 2018. Out of this massive volume, 62 flaws are rated critical, including three zero-days, with two confirmed to be under active exploitation in the wild.

This explosive growth in vulnerability disclosures introduces severe friction for enterprise change management and IT administrators. Traditional testing and deployment workflows struggle to keep pace when faced with such high-volume telemetry. As vendors increasingly leverage automated tooling to unearth flaws, organizations must adapt to a permanent elevation in patch cadence and threat notification volume.

## UAT-11795 and Starland [RAT](/glossary#remote-access-trojan-rat) Campaign Analysis

Concurrent with the flood of software patches, Cisco Talos has detailed an ongoing campaign by a financially motivated, Russian-speaking [threat actor](/glossary#threat-actor) tracked as **UAT-11795**. Active since at least June 2025, this adversary targets enterprise users across the United States and Europe using sophisticated delivery mechanisms.

### Infection Vectors and Tooling

* **Trojanized Installers:** The attackers compromise popular productivity and utility tools, including Webex, Zoom, and MobaXterm, embedding malicious payloads inside seemingly legitimate software packages.
* **Starland RAT:** Initial execution deploys a custom Python-based remote access tool that functions as a staging platform for secondary payloads.
* **WLDR Agent:** A bespoke, in-memory PowerShell command-and-control implant designed to evade traditional signature-based detection.
* **Secondary Payloads:** Once [persistence](/glossary#persistence) is established, the operators deploy tools like CastleStealer and Remcos RAT to harvest high-value credentials and cryptocurrency assets.

To maintain operational resilience, UAT-11795 utilizes advanced evasion techniques, including Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) bypasses, alongside a blockchain-anchored fallback mechanism for command-and-control communication.

## Defensive Recommendations and Mitigations

Defenders operating under the strain of record patch loads and sophisticated threat actor campaigns must prioritize structural resilience and visibility:

* **Tune [Endpoint](/glossary#endpoint) Detection:** Ensure security tooling is explicitly configured to detect in-memory execution, AMSI tampering, and unusual PowerShell scripts running from memory or creating unexpected scheduled tasks.
* **Monitor Suspicious Processes:** Keep a close watch on the execution of native binaries like `mshta.exe` and investigate abnormal network connections tied to administrative software.
* **User Awareness Training:** Educate personnel on the risks of unofficial software downloads and emerging [social engineering](/glossary#social-engineering) strategies such as ClickFix tactics.
* **Streamline [Patch Management](/glossary#patch-management):** Re-evaluate change management queues to rapidly ingest and deploy critical updates, prioritizing zero-days and actively exploited flaws over routine maintenance.

**Related:** [Cisco Talos Previews AI Threats and Warlock Ransomware at Black Hat](/blog/cisco-talos-previews-ai-threats-and-warlock-ransomware-at-black-hat), [OpenAI Model Sandbox Escape Highlights Emerging AI Security Risks](/blog/openai-model-sandbox-escape-highlights-emerging-ai-security-risks)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign
