July 17, 2026
- UAT-11795, a Russian-speaking financially motivated actor, is trojanizing WebEx and Zoom installers to deploy the new in-memory Python Starland RAT and a bespoke PowerShell C2 implant (WLDR), targeting US and European victims for credential and crypto theft (Cisco Talos, BleepingComputer). · Threat Activity
in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands