UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
Summary
A Russia-aligned threat actor, identified as UAC-0099 (also tracked as Earth Sirrush), has deployed a new .NET infostealer and remote access trojan (RAT) named ASHVEIN. This malware has been observed in attacks specifically targeting Ukrainian government personnel.
IFF Assessment
FOE
The discovery and deployment of a new RAT by a state-aligned threat actor targeting government entities represents a significant threat to cybersecurity defenses.
Defender Context
Defenders should be aware of UAC-0099's activities and the capabilities of the newly identified ASHVEIN RAT. This threat actor's focus on government targets, particularly in geopolitical hotspots, suggests a need for heightened vigilance and tailored defenses for public sector organizations.