:

RUSSIAN HACKERS WEAPONIZE WEBEX, ZOOM WITH STARLAND MALWARE

SECURITY DESK2 MIN READ
THU, JUL 16, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Russian threat actor UAT-11795 is distributing trojanized versions of popular video conferencing apps to deploy Starland, a new backdoor capable of stealing credentials and cryptocurrency.

A financially motivated Russian hacking group is exploiting trust in widely-used collaboration software to distribute malware. The threat actor, tracked as UAT-11795, has compromised legitimate WebEx and Zoom applications, embedding them with Starland RAT—a remote access trojan designed to harvest sensitive data. The attack vector leverages the ubiquity of video conferencing platforms in enterprise and remote work environments. Users downloading what appear to be standard WebEx or Zoom installers from compromised or spoofed sources instead receive trojaned versions bundled with the Starland backdoor. Once installed, Starland operates as a credential stealer and cryptocurrency theft tool. The malware can capture login credentials, monitor user activity, and facilitate unauthorized access to infected systems. The backdoor also enables attackers to install additional payloads or maintain persistent access for future exploitation. UAT-11795 operates with financial motivations, suggesting the campaign targets both individual users and organizations with valuable assets. The choice of WebEx and Zoom reflects these applications' prevalence in business environments, where compromised credentials can grant access to sensitive meetings, documents, and infrastructure. Security researchers recommend users verify software downloads from official vendor websites or app stores rather than third-party sources. Organizations should implement application whitelisting, monitor for suspicious process behavior, and enforce credential verification protocols. Endpoint detection and response (EDR) solutions can identify Starland's command-and-control communications. The discovery underscores the importance of securing download sources for widely-distributed software. While WebEx and Zoom themselves remain secure, the attack demonstrates how legitimate applications can serve as distribution vectors when users obtain them from untrusted channels. Users concerned about potential infection should scan systems with updated antimalware tools and change credentials on any accounts accessed from potentially compromised machines.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Inexpensive GPS jamming devices are proliferating globally, disrupting navigation systems across civilian infrastructure. The low cost and easy availability of these tools are creating widespread interference zones.

1H AGOIndustry Desk

Devices promising free movies are recruiting home internet connections into proxy networks without users' knowledge. The trade-off: your bandwidth and privacy.

2H AGOIndustry Desk

QubesOS released a security update addressing a critical vulnerability that allows arbitrary code execution through an error reporting backchannel in the copy-to-VM function. The flaw affects multiple Qubes versions.

6H AGOIndustry Desk

Android devices offer built-in protections against malicious apps, scam calls, and privacy breaches. Activating the correct security settings is essential to maximize these defenses.

7H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.