Threat Intelligence

Russia-Aligned Group Uses New ASHVEIN Malware to Spy on Ukrainian Government Staff

The Hacker News · 9 Oct 2026
Key Takeaway Treat unexpected disk image, DLL or installer files as suspect, keep browsers free of saved passwords where possible, and use endpoint protection that monitors for unusual PowerShell activity.

A Russia-aligned threat actor known as UAC-0099 has been linked to a previously undocumented .NET infostealer and remote access trojan (RAT) called ASHVEIN. TrendAI, which tracks the cluster as Earth Sirrush (previously SHADOW-EARTH-065), says the malware has been used in attacks on Ukrainian government personnel. Its developers internally call it "TelemetryBrowser". It combines credential theft from Chrome and Firefox, screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting and encrypted command-and-control communications.

The malware also hides its instructions inside invisible HTML elements. TrendAI says some variants use a GitHub-based dead drop as a fallback, and delivery methods include DLL sideloading, VHD containers and dedicated .NET droppers. According to TrendAI, five builds were compiled between 8 and 23 October 2025 across three packing variants, and ASHVEIN overlaps functionally with an earlier tool called DRAGSTARE.

UAC-0099 was first documented by CERT-UA in June 2023 and has targeted Ukrainian government, defence, border guard and logistics entities since at least mid-2022. ESET's November 2025 report said the group can act as an initial access broker for Sandworm, a Russian group known for destructive attacks against Ukraine. Over time the actor has moved from PowerShell and Go tools to compiled C# and .NET Reactor-protected binaries hidden inside image files. This summary is based on the opening of the source article only.

UAC-0099 ASHVEIN infostealer RAT Ukraine

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.