Security researchers say a financially motivated Russian threat actor known as UAT-11795 is distributing altered versions of popular meeting software, including Zoom and WebEx, to infect systems with a newly identified backdoor called Starland RAT.

According to the report, the campaign is aimed at theft rather than disruption. Once installed, the malware can give attackers remote access that may be used to collect account credentials and target cryptocurrency-related assets on compromised devices.

The tactic stands out because it hides malicious code inside software that many people and businesses use every day. By disguising malware as trusted collaboration tools, the attackers increase the odds that victims will install the program without noticing anything unusual.

The activity underscores the ongoing risk of downloading software from unverified sources and the appeal of familiar business apps as bait. It also shows how credential theft and crypto-focused cybercrime continue to overlap in targeted malware campaigns.