UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
The Russia-aligned actor UAC-0099 targets Ukrainian government personnel with ASHVEIN, a previously undocumented .NET infostealer and remote access trojan. TrendAI tracks the group as Earth Sirrush, previously SHADOW-EARTH-065, and says the malware hides commands in HTML.
The campaign puts Ukrainian government personnel at risk from previously undocumented malware, underscoring a concrete threat to public-sector systems.