New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT
2026-07-17T14:51:47Z•f34a4891850dec2b67501bf7ad6b3b9c2df946e7ab71a92281ee62cf06ff4fa1
AI-generated malwareAsyncAPICISA KEVCVE-2023-4346CVE-2026-53412Chinese cyber espionage','TencShell' ,"LegacyHive","Windows PrivClaude CodeDeepSeekIoT botnetKNXMicrosoftMobaXtermOracleScattered SpiderSonicWallStarland RATTfL attackTuxBot v3UAT-11795WLDRWebexZoomnpm supply chainsupply-chain compromisetrojanized installers
What happened
Multiple high-impact cyber security developments: a Russian-speaking actor (UAT-11795) is distributing trojanized Zoom, Webex and MobaXterm installers to deploy Starland RAT and the WLDR memory-only implant; CISA expanded its Known Exploited Vulnerabilities (KEV) catalog to include KNX, Oracle, SonicWall and Microsoft issues; two Scattered Spider members were sentenced for the 2024 TfL attack; Palo Alto Unit 42 uncovered TuxBot v3, an AI-created modular IoT botnet; Chinese espionage actors used Claude Code and DeepSeek in intrusions; Zoom patched a critical account-takeover vulnerability (CVE-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f34a4891850dec2b67501bf7ad6b3b9c2df946e7ab71a92281ee62cf06ff4fa1
- Enrichment time
- 2026-07-17T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.