By Interestana AI Editorial — AI-drafted, human-overseen. How we report
UAC-0099 Targets Ukraine With ASHVEIN RAT

The Russia-aligned threat actor identified as UAC-0099 has been linked to the deployment of a newly discovered .NET infostealer and remote access trojan (RAT) designated ASHVEIN. Cybersecurity firm TrendAI has reported that this malware is actively being utilized in cyberattacks aimed at Ukrainian government personnel. TrendAI is monitoring this specific threat actor cluster under the designation Earth Sirrush, which was previously known by the identifier SHADOW-EARTH-065. The ASHVEIN malware is notable for its technique of concealing its command and control (C2) communications within HTML files, a method designed to evade detection by security software and network monitoring tools. This obfuscation technique allows the malware to blend in with legitimate web traffic, making it more challenging for defenders to identify malicious activity. The infostealer component of ASHVEIN is designed to exfiltrate sensitive data from compromised systems, while the RAT functionality provides attackers with persistent access and control over the targeted machines. This allows for further lateral movement within the network, deployment of additional malicious payloads, and deeper reconnaissance. The targeting of Ukrainian government personnel by UAC-0099 indicates a continued focus on state-sponsored espionage and disruption operations. Such attacks often aim to gather intelligence, disrupt government functions, or pave the way for more significant cyber operations. The attribution to UAC-0099, a group with known ties to Russia, aligns with ongoing geopolitical tensions and cyber warfare activities. The development of a custom .NET infostealer and RAT like ASHVEIN suggests a sophisticated and evolving threat actor capable of developing and deploying bespoke tools to achieve their objectives. The use of HTML for C2 obfuscation is a tactic that has been observed in other advanced persistent threat (APT) campaigns, highlighting the adaptive nature of these actors. TrendAI's detailed analysis and attribution provide crucial insights for cybersecurity professionals and government agencies to enhance their defenses against this specific threat. Understanding the TTPs (tactics, techniques, and procedures) employed by UAC-0099, particularly the modus operandi of ASHVEIN, is essential for developing effective countermeasures and incident response strategies. The ongoing nature of these attacks underscores the persistent threat posed by state-sponsored cyber actors to critical infrastructure and government entities globally. The specific details of ASHVEIN's functionality, including its data exfiltration capabilities and remote control features, are critical for understanding the potential impact of a successful compromise. The firm's identification of the threat actor cluster as Earth Sirrush further aids in correlating this activity with broader campaigns and threat intelligence. The reliance on HTML for command and control is a significant detail, as it requires security solutions to have advanced capabilities in inspecting encrypted traffic and identifying anomalous patterns within seemingly benign web content. This incident serves as a reminder of the constant evolution of cyber threats and the need for continuous vigilance and adaptation in cybersecurity defenses.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.