Key Findings Russian-speaking threat actor UAT-11795 has been running a malware campaign since June 2025 targeting users in the U.S. and Europe Campaign distributes trojanized installers for legitimate software including Zoom, Webex, MobaXterm, DBeaver, and FACEIT gaming platform Two newly documented malware families deployed: Starland RAT (Python-based) and WLDR (PowerShell memory-only implant) Initial access achieved through ClickFix social engineering technique Starland RA