MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-08 · via The Hacker News

Russia-aligned UAC-0099 uses new ASHVEIN malware against Ukrainian government staff

Image via The Hacker News
Image via The Hacker News

A threat group aligned with Russia and tracked as UAC-0099 has been connected to a newly identified .NET infostealer and remote access trojan named ASHVEIN. TrendAI said the malware was used in intrusions aimed at Ukrainian government staff. The activity is tracked as Earth Sirrush, previously called SHADOW-EARTH-065.

Expanded Detail

UAC-0099, a group assessed as aligned with Russia, has been linked to ASHVEIN, a newly identified malware family. ASHVEIN combines .NET infostealer and remote access trojan capabilities, according to TrendAI.

TrendAI reported that ASHVEIN appeared in intrusions targeting Ukrainian government personnel. The same activity is tracked as Earth Sirrush, a designation that was formerly SHADOW-EARTH-065. These details frame the finding as a named threat cluster using a fresh toolset against a specific set of victims.

Context

The reported targeting of Ukrainian government staff could affect more than the immediate victims. If credentials or communications are stolen, attackers may gain access to sensitive government systems, potentially disrupting administrative work or exposing data handled by public institutions. That may erode trust in digital government services and increase pressure on agencies to harden defenses. The wider public could feel effects indirectly through service delays or heightened security measures.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML.” Browse more stories.