www.trendaisecurity.com UAC-0099 Targets Ukrainian Government with ASHVEIN Malware
Article Content
- •UAC-0099 is targeting Ukrainian government personnel with the ASHVEIN malware.
- •ASHVEIN combines credential theft, surveillance, and remote access capabilities.
- •The threat actor has evolved its malware arsenal since mid-2022, utilizing various delivery methods.
The Russia-aligned threat actor UAC-0099 has been linked to a new .NET infostealer and RAT named ASHVEIN, targeting Ukrainian government personnel. This malware, also referred to as 'TelemetryBrowser,' features capabilities such as credential theft from Chrome and Firefox, screenshot capture, and remote shell execution. ASHVEIN is part of a broader malware arsenal developed by UAC-0099, which has been active since at least mid-2022, following Russia's full-scale invasion of Ukraine. The group has utilized various delivery methods, including DLL sideloading and VHD containers, and has been involved in spear-phishing campaigns against government and defense entities. TrendAI reports that ASHVEIN overlaps functionally with previous malware like DRAGSTARE but has distinct differences. The threat actor has evolved its tools over the years, transitioning from PowerShell and Go-based malware to .NET-based binaries. The ongoing cyber espionage efforts by UAC-0099 highlight the persistent threat to Ukrainian infrastructure amidst geopolitical tensions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Earth Sirrush, Ashvein and CVE-2023-38831 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is ASHVEIN?
Who is targeted by UAC-0099?
What are the capabilities of ASHVEIN?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…