UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
Overview
UAC-0099, a Russia-aligned hacking group, has been linked to a new malware called ASHVEIN, which functions as both an infostealer and a remote access trojan (RAT). This malware is currently being used in targeted attacks against Ukrainian government personnel. Researchers from TrendAI, who are tracking this activity under the name Earth Sirrush, report that ASHVEIN disguises its commands within HTML, making it harder to detect. This development raises concerns about the security of government systems in Ukraine, particularly given the ongoing geopolitical tensions in the region. As these attacks evolve, it highlights the need for enhanced cybersecurity measures among officials and government staff.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Ukrainian government personnel, government systems
- Action Required: Users should implement enhanced security measures, including regular system updates, network monitoring, and employee training on recognizing phishing attempts.
- Timeline: Newly disclosed
Original Article Summary
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
Impact
Ukrainian government personnel, government systems
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should implement enhanced security measures, including regular system updates, network monitoring, and employee training on recognizing phishing attempts. Specific patches or updates were not mentioned.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware, Trojan.