Find notable cyber news and cases, enriched with sources, timelines, and signals.

ASHVEIN (TelemetryBrowser) .NET infostealer and RAT activity against Ukrainian government personnel

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The ASHVEIN (TelemetryBrowser) malware activity now includes confirmed attacks against Ukrainian government personnel, giving UAC-0099 a new .NET infostealer/RAT for credential theft and remote control. The malware steals logins from Chrome and Firefox while also supporting screenshot capture, file collection, and PowerShell remote shells. Its delivery chain uses DLL sideloading, VHD containers, and dedicated .NET droppers to expand reach and persistence. The build set was actively maintained in October 2025, showing continued development of a flexible intrusion toolset.

Related Happenings

UAC-0099 campaign targeting Ukrainian government, logistics, and infrastructure entities

Campaign
H score33 First: 08.10.2026 18:26 Last: 08.10.2026 18:26 Sources 1

How related: It has a history of targeting Ukrainian government, defense, border guard, and logistics entities since at least mid-2022, emerging in the wake of Russia's full-scale invasion of Ukraine.

About this happening: The UAC-0099 campaign is now tied to a broader targeting set in Ukraine, including civilian logistics and infrastructure operators, which raises the risk to the systems th...

UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets

Campaign
H score24 First: 19.07.2026 16:30 Last: 19.07.2026 16:30 Sources 1

About this happening: Sandworm-linked UAC-0145 is running a ClickFix campaign that uses compromised websites and fake CAPTCHA lures to push Ukrainian targets into executing atta...

ACR Stealer enterprise infostealer surge

Malware Activity
H score29 First: 18.07.2026 17:17 Last: 18.07.2026 17:17 Sources 1

About this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....

Timeline

  1. 08.10.2026 18:26 2 articles · 6h ago

    UAC-0099 attributed to ASHVEIN malware used against Ukrainian government personnel

    Initial Disclosure

    UAC-0099 is attributed to ASHVEIN, a previously undocumented .NET infostealer and remote access trojan internally called TelemetryBrowser, and the malware has been used against Ukrainian government personnel. The malware steals credentials from Chrome and Firefox, captures screenshots, enumerates and retrieves files, runs PowerShell remote shell commands, performs system fingerprinting, and uses encrypted command-and-control communications, with delivery methods including DLL sideloading, VHD containers, and dedicated .NET droppers.

    Show sources