Russia‑aligned UAC‑0099 Deploys New .NET Infostealer RAT Targeting Ukrainian Officials
A cyber‑espionage campaign attributed to the Russia‑aligned threat group known as UAC‑0099 has begun leveraging a previously unknown .NET‑based malware family, codenamed ASHVEIN, against personnel of Ukrainian government agencies.
ASHVEIN combines the capabilities of an infostealer and a remote access trojan. Security researchers note that the tool embeds its command strings inside seemingly innocuous HTML elements, a technique designed to evade conventional detection mechanisms. Built on the Microsoft .NET framework, the malware can harvest credentials, capture screenshots, and provide operators with full interactive control of compromised machines.
The attribution comes from TrendAI, which traced the malware’s code signatures, infrastructure overlaps, and operational patterns back to UAC‑0099. The group has a history of aligning with Russian strategic interests, and analysts say the reuse of custom .NET payloads matches its prior activity. TrendAI’s report, first published by The Hacker News, marks the first public identification of ASHVEIN.
Targeted victims are reported to be employees within Ukrainian ministries and local administrations. While the exact data exfiltrated has not been disclosed, the presence of a remote access component suggests the actors aim to maintain persistent footholds for intelligence gathering and potential sabotage. The campaign underscores the heightened cyber pressure on Ukrainian state structures amid the broader geopolitical conflict.
Cyber operations against Ukraine have intensified since the start of the war, with multiple state‑aligned groups deploying ransomware, wiper malware, and espionage tools. The emergence of ASHVEIN adds a new layer to the threat landscape, illustrating how adversaries continue to develop bespoke malware to bypass evolving defenses.
Security experts advise Ukrainian agencies to reinforce endpoint monitoring, apply strict application whitelisting, and conduct thorough forensic reviews of any anomalous network traffic. International partners are also urged to share indicators of compromise promptly, enabling faster detection and mitigation across the region’s digital frontlines.
Comments (0)
Be the first to comment.
Join the discussion