Russian-speaking group deploys new malware targeting U.S. and European crypto assets
AI-generated from multiple sources. Verify before acting on this reporting.
SAN FRANCISCO — A Russian-speaking cyber adversary identified as UAT-11795 has launched a sophisticated campaign deploying novel remote access trojans against targets in the United States, Germany, Romania, and Venezuela. Cisco Talos disclosed the operation on July 16, 2026, warning that the group is utilizing custom-built malware to steal credentials and cryptocurrency wallet assets from victims across North America and Europe.
The campaign centers on two primary tools: a new variant of remote access software dubbed Starland RAT and a bespoke command-and-control implant known as WLDR. Security researchers indicate these implants are designed for high-level persistence, allowing attackers to maintain long-term access to compromised systems while evading standard detection mechanisms. The group's activities appear strictly financially motivated, with specific focus on accessing digital wallets containing significant cryptocurrency holdings.
Victims in the United States and Germany constitute a primary segment of the targeted demographic, though confirmed incidents have also emerged from Romania and Venezuela. In these locations, users reported unauthorized access to financial accounts shortly after interacting with malicious payloads delivered through social engineering techniques. The Starland RAT enables attackers to execute arbitrary commands on infected machines, while the WLDR implant facilitates covert communication between compromised hosts and attacker servers.
The sophistication of the campaign marks a shift in tactics for UAT-11795, moving beyond opportunistic attacks toward targeted intrusions against individuals holding digital assets. The group's use of bespoke infrastructure suggests an investment in custom development to bypass existing security controls within corporate and personal networks. Unlike previous iterations of similar malware families, this deployment utilizes encrypted channels that complicate forensic analysis and attribution efforts.
Cisco Talos has released indicators of compromise to assist organizations in identifying affected systems. Network administrators are advised to monitor for unusual outbound traffic patterns consistent with the WLDR command-and-control protocol and to scan endpoints for signatures associated with Starland RAT. The disclosure comes as global cybersecurity firms report a rising trend in attacks specifically targeting cryptocurrency infrastructure.
Questions remain regarding the full scope of the campaign's reach, particularly concerning whether additional nations beyond the four identified are under attack. It is also unclear if UAT-11795 has successfully exfiltrated significant volumes of digital currency or if the operation remains in its reconnaissance phase for high-value targets. As defenders work to patch vulnerabilities exploited by this group, security experts warn that further iterations of these tools could emerge as attackers refine their methods.