UAT-11795 is a financially motivated Russian-speaking cybercriminal group known for deploying CastleStealer and Remcos RAT.
Analyst brief
UAT-11795 is a sophisticated, Russian-speaking cybercriminal group motivated by financial gain, active since June 2025. The actor primarily targets users in the U.S. and Europe. Their key TTPs involve deploying CastleStealer and Remcos RAT as alternative payload implants for data theft and remote access. Defenders should focus on detecting indicators for these payloads, anomalous network traffic targeting financial systems, and phishing-based initial infection vectors.
UAT-11795
unknown
UAT-11795 is a sophisticated, Russian-speaking, financially motivated adversary conducting malicious campaigns targeting users in the U.S. and Europe since June 2025. The actor employs CastleStealer and Remcos RAT as alternative payload implants. Their operations indicate a focus on financial gain through targeted attacks.