Russia-aligned UAC-0099 uses new ASHVEIN malware against Ukrainian government staff

A threat group aligned with Russia and tracked as UAC-0099 has been connected to a newly identified .NET infostealer and remote access trojan named ASHVEIN. TrendAI said the malware was used in intrusions aimed at Ukrainian government staff. The activity is tracked as Earth Sirrush, previously called SHADOW-EARTH-065.
UAC-0099, a group assessed as aligned with Russia, has been linked to ASHVEIN, a newly identified malware family. ASHVEIN combines .NET infostealer and remote access trojan capabilities, according to TrendAI.
TrendAI reported that ASHVEIN appeared in intrusions targeting Ukrainian government personnel. The same activity is tracked as Earth Sirrush, a designation that was formerly SHADOW-EARTH-065. These details frame the finding as a named threat cluster using a fresh toolset against a specific set of victims.
The reported targeting of Ukrainian government staff could affect more than the immediate victims. If credentials or communications are stolen, attackers may gain access to sensitive government systems, potentially disrupting administrative work or exposing data handled by public institutions. That may erode trust in digital government services and increase pressure on agencies to harden defenses. The wider public could feel effects indirectly through service delays or heightened security measures.