New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT

2026-07-17T14:51:47Zf34a4891850dec2b67501bf7ad6b3b9c2df946e7ab71a92281ee62cf06ff4fa1
AI-generated malwareAsyncAPICISA KEVCVE-2023-4346CVE-2026-53412Chinese cyber espionage','TencShell' ,"LegacyHive","Windows PrivClaude CodeDeepSeekIoT botnetKNXMicrosoftMobaXtermOracleScattered SpiderSonicWallStarland RATTfL attackTuxBot v3UAT-11795WLDRWebexZoomnpm supply chainsupply-chain compromisetrojanized installers

What happened

Multiple high-impact cyber security developments: a Russian-speaking actor (UAT-11795) is distributing trojanized Zoom, Webex and MobaXterm installers to deploy Starland RAT and the WLDR memory-only implant; CISA expanded its Known Exploited Vulnerabilities (KEV) catalog to include KNX, Oracle, SonicWall and Microsoft issues; two Scattered Spider members were sentenced for the 2024 TfL attack; Palo Alto Unit 42 uncovered TuxBot v3, an AI-created modular IoT botnet; Chinese espionage actors used Claude Code and DeepSeek in intrusions; Zoom patched a critical account-takeover vulnerability (CVE-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f34a4891850dec2b67501bf7ad6b3b9c2df946e7ab71a92281ee62cf06ff4fa1
Enrichment time
2026-07-17T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.