negativeSYS.SOURCE: The Hacker News• 2026-10-08T20:56:56+05:30
UAC-0099 Conducts Cyber Espionage Against Ukrainian Government Using ASHVEIN RAT Malware
A Russia-aligned threat group, UAC-0099, has been linked to a new .NET infostealer and RAT named ASHVEIN, targeting Ukrainian government personnel. The malware employs HTML-based command hiding, as reported by TrendAI under the Earth Sirrush tracking cluster.
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN.
According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065).
ASHVEIN,
*** END OF TRANSMISSION ***