Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
UAC-0099 Deploys ASHVEIN RAT Against Ukraine

UAC-0099 Deploys ASHVEIN RAT Against Ukraine

Posted on October 8, 2026 By CWS

The cybersecurity threat group known as UAC-0099 has been linked to a newly identified .NET-based malware called ASHVEIN. This remote access trojan (RAT) has been actively used in attacks against Ukrainian government officials. TrendAI, a cybersecurity firm, has labeled this cluster as Earth Sirrush, previously known as SHADOW-EARTH-065.

ASHVEIN’s Capabilities and Deployment

ASHVEIN, internally called ‘TelemetryBrowser,’ integrates several malicious functionalities, including credential theft from popular browsers like Chrome and Firefox, the ability to capture screenshots using GDI, and remote control through PowerShell. Additionally, it utilizes encrypted command-and-control (C2) communications, making it a versatile tool for cyber espionage.

TrendAI reports that ASHVEIN conceals its operations within invisible HTML elements. Different versions of the malware have employed a GitHub-based resolver as a secondary tactic, while its distribution methods encompass DLL sideloading, VHD containers, and specialized .NET droppers.

Historical Context and Evolution

First documented by CERT-UA in June 2023, UAC-0099 has a history of targeting Ukrainian governmental and military sectors, particularly since mid-2022. The group’s activities have intensified following Russia’s extensive military actions in Ukraine.

According to ESET, a cybersecurity provider, UAC-0099 may function as an initial access facilitator for the Russian APT group Sandworm. Over time, the group has diversified its malware portfolio, transitioning from PowerShell- and Go-based tools to more secure C# and .NET binaries, often hidden within image files.

Recent Developments and Tactical Shifts

Recent malware families linked to UAC-0099 include LONEPAGE, THUMBCHOP, and most recently, ASHVEIN. Between October 8 and October 23, 2025, five ASHVEIN builds were compiled using three different packing techniques. Despite functional similarities with DRAGSTARE, such as credential theft and file collection, significant differences in their development environments suggest parallel tool creation.

UAC-0099 employs varied delivery methods for ASHVEIN, including the use of decoy documents like AnswerFromPolice, which masquerades as official communication from the Ukrainian National Police. This tactic aims to increase the likelihood of the malware being executed by unsuspecting users.

Implications and Future Outlook

The ongoing activities of UAC-0099 highlight a sophisticated and evolving threat landscape. Their ability to adapt and enhance their malware arsenal poses a significant challenge to cybersecurity defenses. With the conflict in Ukraine continuing, understanding and disrupting these cyber operations remains crucial.

As the threat actor extends its focus beyond military targets to civilian infrastructure, the need for robust cybersecurity measures grows. The evolving tactics, such as the recent employment of GuardBreaker to bypass AI-based analysis, underline the importance of continuous vigilance and advanced threat detection capabilities.

The Hacker News Tags:ASHVEIN, CERT-UA, cyber espionage, Cybersecurity, ESET, Malware, RAT, TrendAI, UAC-0099, Ukraine

Post navigation

Previous Post: Malware Hides on Blockchain via Fake Hotel Reviews
Next Post: Cisco Releases Patches for Critical Security Flaws

Related Posts

Pegasus Zero-Click Spyware Targeted Serbian Activists Pegasus Zero-Click Spyware Targeted Serbian Activists The Hacker News
Azure CLI Targeted by Extensive Password Spray Attack Azure CLI Targeted by Extensive Password Spray Attack The Hacker News
175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign The Hacker News
Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE Flaws Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE Flaws The Hacker News
New Cyber Threat OP-512 Hits Microsoft IIS Servers New Cyber Threat OP-512 Hits Microsoft IIS Servers The Hacker News
Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure
  • AI Tool ARTEX Exploited in South Korean Data Breaches
  • Critical LMCache Vulnerability Allows Unauthorized Code Execution
  • Cisco Releases Patches for Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure
  • AI Tool ARTEX Exploited in South Korean Data Breaches
  • Critical LMCache Vulnerability Allows Unauthorized Code Execution
  • Cisco Releases Patches for Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark