ASHVEIN (TelemetryBrowser) .NET infostealer and RAT activity against Ukrainian government personnel
Malware Activity
Summary
Hide ▲
Show ▼
The ASHVEIN (TelemetryBrowser) malware activity now includes confirmed attacks against Ukrainian government personnel, giving UAC-0099 a new .NET infostealer/RAT for credential theft and remote control. The malware steals logins from Chrome and Firefox while also supporting screenshot capture, file collection, and PowerShell remote shells. Its delivery chain uses DLL sideloading, VHD containers, and dedicated .NET droppers to expand reach and persistence. The build set was actively maintained in October 2025, showing continued development of a flexible intrusion toolset.
Related Happenings
UAC-0099 campaign targeting Ukrainian government, logistics, and infrastructure entities
Campaign
H score33
First: 08.10.2026 18:26
Last: 08.10.2026 18:26
Sources 1
How related:
It has a history of targeting Ukrainian government, defense, border guard, and logistics entities since at least mid-2022, emerging in the wake of Russia's full-scale invasion of Ukraine.
About this happening:
The UAC-0099 campaign is now tied to a broader targeting set in Ukraine, including civilian logistics and infrastructure operators, which raises the risk to the systems th...
UAC-0099 campaign targeting Ukrainian government, logistics, and infrastructure entities
CampaignHow related: It has a history of targeting Ukrainian government, defense, border guard, and logistics entities since at least mid-2022, emerging in the wake of Russia's full-scale invasion of Ukraine.
About this happening: The UAC-0099 campaign is now tied to a broader targeting set in Ukraine, including civilian logistics and infrastructure operators, which raises the risk to the systems th...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
Campaign
H score24
First: 19.07.2026 16:30
Last: 19.07.2026 16:30
Sources 1
About this happening:
Sandworm-linked UAC-0145 is running a ClickFix campaign that uses compromised websites and fake CAPTCHA lures to push Ukrainian targets into executing atta...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
CampaignAbout this happening: Sandworm-linked UAC-0145 is running a ClickFix campaign that uses compromised websites and fake CAPTCHA lures to push Ukrainian targets into executing atta...
ACR Stealer enterprise infostealer surge
Malware Activity
H score29
First: 18.07.2026 17:17
Last: 18.07.2026 17:17
Sources 1
About this happening:
ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ACR Stealer enterprise infostealer surge
Malware ActivityAbout this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
Timeline
-
08.10.2026 18:26 2 articles · 6h ago
UAC-0099 attributed to ASHVEIN malware used against Ukrainian government personnel
Initial DisclosureUAC-0099 is attributed to ASHVEIN, a previously undocumented .NET infostealer and remote access trojan internally called TelemetryBrowser, and the malware has been used against Ukrainian government personnel. The malware steals credentials from Chrome and Firefox, captures screenshots, enumerates and retrieves files, runs PowerShell remote shell commands, performs system fingerprinting, and uses encrypted command-and-control communications, with delivery methods including DLL sideloading, VHD containers, and dedicated .NET droppers.
Show sources
- UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML — thehackernews.com — 08.10.2026 18:26
- UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML — thehackernews.com — 08.10.2026 18:26