UPDATES
threat
UPDATES
RUSSIA
Researchers at Cisco Talos have identified a malware campaign linked to the financially motivated Russian threat actor UAT- 11795, which has been using trojanised software installers to deploy a new backdoor known as Starland RAT.
According to the researchers, the campaign has been active since at least June 2025 and has primarily targeted users in the US, although victims have also been identified in Germany, Romania and Venezuela.
The threat actor is reported to distribute the malware through compromised installers for legitimate applications including MobaXterm, WebEx, Zoom, DBeaver and FaceIT. Once installed, the malware is designed to steal user credentials and cryptocurrency.
Dray Agha, Senior Manager, Security Operations Center – EMEA at Huntress, said:“ By hiding the Starland RAT inside trusted software and likely utilising deceptive‘ ClickFix’ social engineering tactics, these threat actors are completely bypassing traditional perimeter defences to exploit human psychology rather than software vulnerabilities.”
IRAN
Iran is increasingly using Artificial Intelligence to enhance cyber-operations, information campaigns and military activities, according to new research from Recorded Future’ s Insikt Group.
The report examines how AI is being used to support Iran’ s wider hybrid warfare strategy, concluding that the technology is acting as a force multiplier by increasing the speed and scale of cyber-operations, military activity, information warfare and state influence campaigns.
According to the research, Iran’ s AI capabilities appear to have been strengthened through co-operation with Russia and China. The report advises organisations, particularly those operating critical infrastructure, to strengthen defences against AI-assisted phishing campaigns, cyber-intrusions targeting operational technology( OT) environments and influence operations.
An analyst at Recorded Future’ s Insikt Group said:“ The 2026 crisis likely prompted Iranian state-sponsored and state-aligned threat actors to leverage Generative AI to gain productivity and tradecraft improvements across reconnaissance, code / malware development, social engineering and translation. However, AI has not fundamentally shifted Iranian cyber-capability, it is scaling and accelerating what Iranian actors were already doing.”
WWW. INTELLIGENTCISO. COM 35