#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
Discover the best posts from developers and engineering teams, all in one place.
Join now
→
Learn more
TOPICS
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
34
·
Blog Talosintelligence
·
July 16, 2026, 3:50 p.m.
Threats
rat
Cisco Talos Antivirus
Cisco Talos DNS Security
Cybersecurity
malware
Remote Access Trojans
financial crimes
Summary
Cisco Talos reveals a sophisticated financial cyber campaign by the Russian-speaking group UAT-11795, targeting users in the U.S. and Europe since June 2025, utilizing a novel remote access tool (RAT) and a bespoke command-and-control (C2) implant.
Read full post on blog.talosintelligence.com →
MORE POSTS LIKE THIS
security: ACR Stealer: Two observed intrusion chains amid increased threat activity
Sujith Quintelier ·
Jul 17, 2026
ACR Stealer
malware
BlackToad Threat Actors Deploy Stealthy Phishing Lures
Securityonline ·
Jun 2, 2026
Cybercriminals
BlackToad
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
Blog Talosintelligence ·
May 19, 2026
Threat Spotlight
Cisco Talos Malware Protection
The Good, the Bad and the Ugly in Cybersecurity – Week 17
Sentinelone ·
Apr 24, 2026
Company
Cyber
Admitting the Elephantine Void Between Kinetic and Cyber Threats
Flying Penguin Blog ·
Jul 22, 2026
Energy
history
Fake GitHub repositories exploit developer trust to spread malware
Developer Tech ·
Jul 17, 2026
Build & Ship
Cybersecurity & Development
Discover more posts →
AUTHOR
BLOG POST FEATURED ON
r/blueteamsec
2 points
r/purpleteamsec
2 points
r/worldTechnology
1 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google