Russian Threat Actor Targets WebEx and Zoom Users With Trojanized Installers

A financially motivated Russian threat actor tracked as UAT-11795 has been distributing trojanized versions of WebEx and Zoom installers to deliver a new backdoor called Starland RAT, according to cybersecurity researchers.

The attackers modified legitimate installer files for the popular video conferencing applications, embedding the malware into the setup process. When users download and run what appears to be a genuine WebEx or Zoom installer, the malicious code executes alongside the legitimate installation, giving the attackers a foothold on the victim’s system.

Security firms identified the campaign through analysis of the trojanized installers, which were distributed through spear-phishing emails and compromised websites. The emails were crafted to appear as if they came from trusted sources, urging recipients to install or update their video conferencing software.

The Starland RAT backdoor provides attackers with extensive control over compromised systems. It can steal browser credentials, cryptocurrency wallet data, and other sensitive information, as well as download and execute additional payloads. The malware communicates with command-and-control servers hosted on infrastructure linked to Russian threat actors.

The campaign highlights an ongoing trend of threat actors exploiting the widespread use of collaboration tools in enterprise environments. Video conferencing applications, which saw massive adoption during the pandemic, remain a key attack vector because they are typically installed on enterprise networks with broad access and are frequently updated, creating opportunities for attackers to intercept or replace legitimate downloads.

Organizations are advised to download software only from official vendor websites, verify digital signatures on installer files, and implement application whitelisting to prevent execution of unauthorized software.

This article was adapted from Bleeping Computer. Read the original here.