LIVE · cybersecurity feed
Live wire
malware

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

A Russia-aligned threat actor, UAC-0099, has reportedly been observed deploying a new .NET-based infostealer and remote access trojan (RAT) named ASHVEIN. This malware has been specifically used in attacks targeting Ukrainian government personnel. The cybersecurity firm TrendAI is tracking this activity cluster under the designation Earth Sirrush, which was previously known as SHADOW-EARTH-065.

ZeroDay News ·

Source: The Hacker News

A Russia-aligned threat actor, UAC-0099, has reportedly been observed deploying a new .NET-based infostealer and remote access trojan (RAT) named ASHVEIN. This malware has been specifically used in attacks targeting Ukrainian government personnel. The cybersecurity firm TrendAI is tracking this activity cluster under the designation Earth Sirrush, which was previously known as SHADOW-EARTH-065.

The ASHVEIN malware is notable for its technique of hiding commands within HTML content, a method that could potentially evade some traditional security detections. This approach involves embedding malicious instructions in what might appear to be benign web content, making it more challenging for automated analysis tools to flag the embedded commands as suspicious. Once executed, the malware functions as both an infostealer, designed to exfiltrate sensitive data, and a RAT, providing remote control capabilities to the attackers.

As a .NET infostealer, ASHVEIN likely targets a range of data types commonly found on compromised systems. This typically includes credentials, browser histories, financial information, and documents. The remote access capabilities would allow UAC-0099 to maintain persistence on infected machines, execute further commands, download additional payloads, and potentially move laterally within a network. The use of .NET frameworks is common among malware developers due to its versatility and the widespread presence of .NET runtime environments on Windows systems.

The targeting of Ukrainian government personnel by UAC-0099 aligns with broader geopolitical motivations often attributed to Russia-aligned threat actors. Such campaigns frequently aim to gather intelligence, disrupt operations, or sow discord. Attacks against government entities are particularly sensitive due to the potential for national security implications and the compromise of classified or highly confidential information.

Mitigation strategies for this class of threat typically involve a multi-layered approach. Organizations are advised to implement robust email and web filtering to block malicious attachments and links, as initial infection vectors often involve phishing. Endpoint detection and response (EDR) solutions are crucial for identifying and responding to suspicious activity on endpoints, especially for detecting novel malware like ASHVEIN. Regular security awareness training for personnel, particularly those in high-risk roles, is also vital to help them recognize and report social engineering attempts.

Furthermore, network segmentation can limit lateral movement should an initial compromise occur, and strong access controls, including multi-factor authentication (MFA), can prevent unauthorized access to critical systems even if credentials are stolen. Patch management is also important to address vulnerabilities that could be exploited by other attack stages or different malware variants.

This incident underscores the ongoing and evolving threat landscape faced by critical sectors, particularly in regions experiencing geopolitical conflict. The continuous development of new malware and evasion techniques by sophisticated threat actors like UAC-0099 necessitates constant vigilance and adaptation in cybersecurity defenses. The use of novel command hiding techniques highlights the need for advanced threat detection capabilities that can analyze content beyond superficial inspection.

malwareai
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.

vulnerability

Chasing AMMYY at Splunk .conf

A recent report detailed the detection of Flawed AMMYY RAT traffic at the Splunk .conf event, an incident uncovered through the combined capabilities of Cisco's Encrypted Visibility Engine (EVE) and Endace PCAP. The key takeaway from this discovery was the ability to identify this malicious activity without the need to decrypt TLS-encrypted communications, highlighting advancements in network…

breachcritical

Cisco Patches a Dozen Critical Vulnerabilities

Cisco has released patches addressing a dozen critical vulnerabilities across its product line. These security defects reportedly encompass a range of potential impacts, including unauthorized access, information leaks, privilege escalation, denial-of-service (DoS) attacks, and remote code execution (RCE). The widespread nature of these reported flaws suggests a significant security update…

vulnerabilitycritical

Cisco warns of critical flaws allowing Nexus switch takeover

Cisco has issued a warning regarding five critical vulnerabilities identified in its NX-OS data center network operating system, which could enable attackers to execute arbitrary code with root privileges on Nexus switches. In scenarios where remote code execution is not achievable, exploitation of these flaws could lead to process crashes and device reloads, resulting in denial-of-service…

cloud

Admin in the Loop: Firewalls and the Agentic SOC

A recent report details the integration of Cisco Secure Firewall and Cloud Control with Splunk ES, specifically highlighting its role in feeding structured Snort 3 and EVE telemetry into an "Agentic SOC pipeline." This integration is presented as a foundational element for advanced security operations, leveraging automated data streams for analysis and response.

ai

Who watches the AI watching your street?

Yusaku Fujii, a professor at Gunma University in Japan, has developed a system designed to audit and penalize the misuse of artificial intelligence that analyzes street camera footage. His proposal, called the Verifiable Record of AI Output (VRAIO), aims to ensure accountability for AI systems operating in what he terms Fully Monitored Public Spaces (FMPS), areas with dense camera coverage…