Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Russian threat actor UAT-11795 is distributing trojanized versions of WebEx and Zoom applications to deploy Starland RAT malware for credential theft and cryptocurrency theft. The campaign targets users of these widely-used communication platforms.
- Disclosed
- Last updated
- Blast radius
- Unknown; potentially widespread given trojanization of popular communication tools (WebEx, Zoom)
- Ecosystems
- Attack vectors
- Affected entities
- WebExTrojanized versions distributed by threat actor UAT-11795
- ZoomTrojanized versions distributed by threat actor UAT-11795
A financially motivated Russian threat actor tracked as UAT-11795 has been observed trojanizing legitimate WebEx and Zoom applications to distribute a new backdoor malware called Starland RAT. The trojanized software is being used to steal credentials and cryptocurrency from victims.
The use of trojanized versions of popular communication tools represents a significant supply chain risk, as users may unknowingly download compromised installers or updates. The Starland RAT backdoor provides attackers with remote access capabilities to infected systems.
The campaign appears to be ongoing, with the threat actor actively distributing these trojanized applications to target users relying on WebEx and Zoom for business and personal communications.
Remediation
- Verify the integrity of WebEx and Zoom installations by downloading directly from official vendor websites (webex.com, zoom.us) rather than third-party sources
- Check file hashes against official vendor-provided checksums to ensure authenticity
- Monitor for signs of Starland RAT infection including unexpected network connections and credential access attempts
- Implement application whitelisting to prevent unauthorized executables from running
- Use endpoint detection and response (EDR) tools to identify and isolate infected systems
- Reset credentials for any accounts accessed from potentially compromised systems
- Keep WebEx and Zoom applications updated to the latest official versions
Sources
- Russian hackers trojanize WebEx, Zoom apps to push Starland malware · BleepingComputer
Cite this entry
"Russian hackers trojanize WebEx, Zoom apps to push Starland malware." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 16, 2026; last updated July 16, 2026. https://supplychainattack.org/incident/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-p7zss7
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.
ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover - containedhigh
Online ad firm Adform’s script compromised to steal cryptocurrency
Adform's advertising script was compromised in a supply-chain attack that injected cryptocurrency-stealing code. The malicious script intercepted wallet addresses copied to visitors' clipboards and replaced them with attacker-controlled addresses, affecting all websites using Adform's ad platform.
OtherCompromised package - containedcritical
Malicious code in @antv/l7-mapkit (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-mapkit, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-assets-tugraph (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-assets-tugraph was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit