
This episode discusses a Russian-speaking financial threat actor and their cyber activities targeting the US and Europe.
🐛 Cisco Talos documente UAT-11795, un acteur russophone à motivation financière actif depuis juin 2025 visant les États-Unis et l’Europe. Le groupe déploie le RAT Python Starland et l’implant C2 en mémoire WLDR agent, avec CastleStealer et Remcos RAT en charges alternatives. L’accès initial repose sur la technique ClickFix et des installateurs trojanisés (MobaXterm, WebEx, […]
Host: Radio CSIRT
Organizations: Cisco Talos, UAT-11795
Products: RAT Python Starland, WLDR agent, CastleStealer, Remcos RAT, ClickFix, MobaXterm, WebEx
Places: États-Unis, Europe
Explore listener stats, chart rankings, contacts and more on the RadioCSIRT podcast page.