RC RANDOM CHAOS

Russia-Aligned Hackers Deploy ASHVEIN RAT Against Ukraine

· via The Hacker News

Original source

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Hacker News →

The threat group UAC-0099, linked to Russia, has launched a new .NET-based malware called ASHVEIN to target Ukrainian government employees. This remote access trojan combines credential theft, surveillance, and remote control capabilities, hiding commands in HTML elements and using GitHub for fallback mechanisms. The group has been active since mid-2022, primarily targeting government, defense, and logistics entities in Ukraine.

ASHVEIN is part of a broader malware arsenal that includes several other tools developed and evolved by UAC-0099 over the years. The group has shifted from PowerShell and Go-based tools to C# and .NET Reactor-protected binaries. They employ various delivery methods, such as DLL sideloading, VHD containers, and dedicated .NET droppers, often using decoy documents to trick victims. The malware has also evolved to include techniques like GuardBreaker, designed to evade AI-assisted analysis by triggering safety mechanisms in large language models.

Read the full article

Continue reading at The Hacker News →

This is an AI-generated summary. Read the original for the full story.