#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
34
·
Blog Talosintelligence
·
July 16, 2026, 3:50 p.m.
Threats
rat
Cisco Talos Antivirus
Cisco Talos DNS Security
Cybersecurity
malware
Remote Access Trojans
financial crimes
Summary
Cisco Talos reveals a sophisticated financial cyber campaign by the Russian-speaking group UAT-11795, targeting users in the U.S. and Europe since June 2025, utilizing a novel remote access tool (RAT) and a bespoke command-and-control (C2) implant.
Read full post on blog.talosintelligence.com →
MORE POSTS LIKE THIS
security: ACR Stealer: Two observed intrusion chains amid increased threat activity
Sujith Quintelier ·
Jul 17, 2026
ACR Stealer
malware
BlackToad Threat Actors Deploy Stealthy Phishing Lures
Securityonline ·
Jun 2, 2026
Cybercriminals
BlackToad
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
Blog Talosintelligence ·
May 19, 2026
Threat Spotlight
Cisco Talos Malware Protection
The Good, the Bad and the Ugly in Cybersecurity – Week 17
Sentinelone ·
Apr 24, 2026
Company
Cyber
Admitting the Elephantine Void Between Kinetic and Cyber Threats
Flying Penguin Blog ·
Jul 22, 2026
Energy
history
Fake GitHub repositories exploit developer trust to spread malware
Developer Tech ·
Jul 17, 2026
Build & Ship
Cybersecurity & Development
Discover more posts →
AUTHOR
BLOG POST FEATURED ON
r/blueteamsec
2 points
r/purpleteamsec
2 points
r/worldTechnology
1 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google