Russian Hackers Trojanize WebEx and Zoom Apps to Spread Starland Malware

Russian cybercriminals trojanize WebEx and Zoom to proliferate Starland RAT. They steal credentials and cryptocurrencies. Know how to protect yourself.

viernes, 17 de julio de 2026 • 5 min read • Q2BSTUDIO Team

Russian actor UAT-11795 deploys Starland RAT backdoor

In a scenario where digital transformation has led millions of people to rely on video conferencing tools like WebEx and Zoom, cybercriminals have been quick to exploit that trust. Recently, a campaign attributed to a Russian threat actor, known internally as UAT-11795, has been identified as distributing trojanized versions of these popular programs with the aim of stealing credentials and cryptocurrencies by implanting a new backdoor dubbed Starland RAT. Not only does this attack represent a sophisticated social engineering operation, but it also underscores the need to rethink cybersecurity strategies in an increasingly remote business environment.

The mechanics of the attack are deceptively simple: hackers modify legitimate WebEx and Zoom installers, inject the malicious payload, and publish them on official-looking websites or distribute them via targeted phishing campaigns. The user, confident in the reputation of the application, downloads and installs the software without suspecting that it is opening the door to a persistent threat. Once executed, Starland RAT deploys multiple capabilities: screen capture, keylogging, local file theft, and, especially worryingly, extracting private keys from cryptocurrency wallets. This type of malicious software operates in the background, exfiltrating sensitive information without raising suspicion until the damage is done.

From a technical perspective, the sophistication of Starland RAT lies in its modularity and its ability to evade traditional detection. It uses code obfuscation techniques, encrypted communication with command and control (C2) servers, and persistence mechanisms that allow it to reboot after a system shutdown. In addition, attackers have demonstrated a deep understanding of corporate workflows: by focusing on collaboration tools, they maximize impact, as these applications often have elevated permissions and access to internal company resources. It's no coincidence that they've chosen WebEx and Zoom, two platforms with a massive user base in corporate environments.

For organizations, this campaign is a wake-up call about the vulnerability of the software supply chain. It's not enough to rely on apps downloaded from external sources to be secure. It is necessary to implement application control policies, digital signature verification and, above all, to have advanced cybersecurity solutions that can detect anomalous behavior even in apparently legitimate software. In this context, investment in security is not an expense, but a strategic necessity.

Today's landscape demands that companies take a holistic approach. Cybersecurity can no longer be limited to installing an antivirus; it must be integrated into each layer of the technological infrastructure. This is where specialized services come into play. For example, having cybersecurity and pentesting services allows you to identify specific vulnerabilities before attackers exploit them. Regular pentesting, along with behavioral analysis and continuous monitoring, can detect the presence of backdoors like Starland RAT before a massive data theft occurs.

In addition, the management of technological infrastructure plays a crucial role. Many companies have migrated their environments to the cloud, and security in those environments needs to be just as rigorous. AWS and Azure cloud services offer built-in security tools, but they require expertise to set them up correctly. A misfit in storage permissions or firewall rules can expose critical data. That's why delegating to professionals who are proficient in cloud architecture is a smart move.

Another aspect that is gaining strength is artificial intelligence applied to security. Machine learning algorithms can analyze network traffic patterns and detect RAT-like anomalies, even when the malware uses encryption. AI for business is no longer a futuristic promise; It is a real tool that allows you to automate incident response. AI agents, for example, can automatically isolate an infected computer before the attacker manages to move laterally within the network. Q2BSTUDIO integrates these capabilities into its solutions, combining custom application development with a security-by-design approach.

Likewise, business intelligence and the use of Power BI become unexpected allies for cybersecurity. By centralizing event logs, security alerts, and performance metrics into interactive dashboards, IT teams can visualize the status of the infrastructure in real time. A well-designed dashboard can alert you to an unusual increase in outbound traffic, typical of data exfiltration. Business intelligence services help transform raw data into actionable insights, accelerating decision-making.

The response to this threat should not only be reactive. Enterprises should consider custom application development as a way to reduce the attack surface. When using generic applications, such as trojanized versions of WebEx, you are completely dependent on the security of the vendor. On the other hand, having custom software developed under security standards allows you to have total control over the code and dependencies. Q2BSTUDIO, as a software and technology development company, offers just that: customized solutions that are tailored to each customer's specific needs, including the integration of robust security protocols.

However, user awareness remains the weakest link. Phishing campaigns distributed by these trojanized installers often employ elaborate social engineering techniques, such as emails mimicking internal IT communications or urgent update alerts. Training employees to identify red flags—such as suspicious domains, misspellings, or unusual requests—is an investment that pays off in spades. The combination of advanced technology and human training creates a much stronger barrier.

Looking ahead, we are likely to see an increase in these types of attacks targeting productivity tools. Threat actors understand that user trust is the most effective entry vector. Therefore, the cybersecurity industry must evolve towards defense-in-depth models, where each layer – from the endpoint to the cloud – is protected and monitored. On this path, collaboration with external experts becomes indispensable.

In short, the emergence of the Starland RAT through trojanized WebEx and Zoom applications is a reminder that digital security should never be taken for granted. Organizations that have not yet implemented proactive cybersecurity measures are playing Russian roulette. At Q2BSTUDIO, we understand that each client has a unique risk profile, and that is why we offer a portfolio of services that ranges from security auditing to the development of secure applications, including the implementation of robust cloud infrastructures and the integration of artificial intelligence to detect threats in real time. Prevention is the best defense, and in a world where attacks are increasingly sophisticated, having reliable technology allies makes all the difference.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.