Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

New Russian-speaking threat actor UAT-11795 targets US and Europe with novel malware

A new Russian-speaking threat actor, tracked as UAT-11795, is targeting US and European organizations using social engineering to trick users into executing commands that download weaponized HTA files, leading to trojanized software installers. The group employs novel tools like the Python-based Starland RAT and the in-memory WLDR agent to exfiltrate credentials, browser data, and cryptocurrency assets, establishing persistent access and even using a blockchain smart contract for C2. Cybersecurity experts advise caution with software sources, verifying downloads, and monitoring for unexpected processes to mitigate this threat.
Read Full Article →

Threat Intelligence New Russian-speaking threat actor UAT-11795 targets US and Europe with novel malware July 17, 2026 Share By SC Staff (Adobe Stock) Coverage from IT Pro indicates a new Russian-speaking threat actor, tracked as UAT-11795, is aggressively targeting victims across the United States and Europe. This group has been active since June of last year, employing trojanized installers for legitimate software to steal credentials and cryptocurrency, according to Cisco Talos. UAT-11795 utilizes novel tools, including the Python-based Starland RAT and the PowerShell-based WLDR agent, which operates entirely in-memory with encrypted beaconing and a Runspace execution engine. Both tools are designed to exfiltrate credentials, browser data, and cryptocurrency wallet assets, while establishing persistent access. Cisco Talos reported that the group even hides a fallback command-and-control channel within a Polygon smart contract. Infections have been primarily observed in the US, but also in Germany, Romania, and Venezuela. The group gains initial access through social engineering tactics, tricking users into executing a command that downloads a weaponized HTA file, leading to the installation of trojanized software. Cybersecurity experts note this campaign highlights a shift in attack vectors, exploiting user trust in legitimate software and social engineering over traditional software vulnerabilities. Users are advised to exercise caution, verify software sources, and monitor for unexpected processes. Source: IT Pro SC Staff Related Threat Intelligence 2 charged in New York for laundering $43 million from investment scams SC Staff July 17, 2026 Zhuoying Chen, 27, and Haojie Zhang, 38, are accused of managing a network that transferred at least $43 million to China, based on information published by Bleeping Computer. EDR How to Evaluate Threat Intelligence and Threat Management Platforms SC Media Editorial Intelligence, reviewed by Dustin Sachs July 17, 2026 Platform success depends on turning findings into operational improvements EDR Threat Intelligence Does Not Equal Threat Readiness SC Media Editorial Intelligence, reviewed by Dustin Sachs July 17, 2026 Five specific failure patterns develop when conversion architecture is missing Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Backdoor Black Hat Deauthentication Attack Dictionary Attack Distributed Scans Domain Hijacking Google Hacking Information Warfare Password Cracking Reconnaissance You can skip this ad in 5 seconds

Share this article