UAC-0099 campaign targeting Ukrainian government, logistics, and infrastructure entities
Campaign
Summary
Hide ▲
Show ▼
The UAC-0099 campaign is now tied to a broader targeting set in Ukraine, including civilian logistics and infrastructure operators, which raises the risk to the systems that keep supply lines running. The operation has targeted government, defense, border guard, and logistics entities since at least mid-2022. It has also used ASHVEIN to collect credentials, capture screenshots, and open remote shells on victim systems. The actor's evolving tooling and widening victim set point to a persistent espionage operation with growing strategic reach.
Related Happenings
ASHVEIN (TelemetryBrowser) .NET infostealer and RAT activity against Ukrainian government personnel
Malware Activity
H score29
First: 08.10.2026 18:26
Last: 08.10.2026 18:26
Sources 1
How related:
According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel.
About this happening:
The ASHVEIN (TelemetryBrowser) malware activity now includes confirmed attacks against Ukrainian government personnel, giving UAC-0099 a new .NET infostealer/RAT f...
ASHVEIN (TelemetryBrowser) .NET infostealer and RAT activity against Ukrainian government personnel
Malware ActivityHow related: According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel.
About this happening: The ASHVEIN (TelemetryBrowser) malware activity now includes confirmed attacks against Ukrainian government personnel, giving UAC-0099 a new .NET infostealer/RAT f...
GTG-30006 Claude-assisted malware and phishing pipeline
Malware Activity
H score20
First: 11.09.2026 17:29
Last: 11.09.2026 17:29
Sources 1
About this happening:
An Iranian actor, GTG-30006, used Claude.ai to build malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, increasing the risk of ...
GTG-30006 Claude-assisted malware and phishing pipeline
Malware ActivityAbout this happening: An Iranian actor, GTG-30006, used Claude.ai to build malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, increasing the risk of ...
Sandworm fake recruiter campaign targeting Ukrainian IT workers
Campaign
H score32
First: 11.08.2026 21:36
Last: 11.08.2026 21:36
Sources 1
About this happening:
CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine si...
Sandworm fake recruiter campaign targeting Ukrainian IT workers
CampaignAbout this happening: CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine si...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Timeline
-
08.10.2026 18:26 2 articles · 6h ago
UAC-0099 deploys ASHVEIN against Ukrainian government personnel and logistics operators
Initial DisclosureUAC-0099, also tracked as Earth Sirrush and SHADOW-EARTH-065, is tied to ASHVEIN/TelemetryBrowser, a .NET infostealer and RAT used against Ukrainian government personnel. The campaign has targeted Ukrainian government, defense, border guard, logistics, and civilian logistics and infrastructure operators since at least mid-2022, and ASHVEIN steals credentials from Chrome and Firefox, captures screenshots, enumerates and retrieves files, runs PowerShell remote shells, hides tasking inside invisible HTML elements, and is delivered through DLL sideloading, VHD containers, and purpose-built .NET droppers.
Show sources
- UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML — thehackernews.com — 08.10.2026 18:26
- UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML — thehackernews.com — 08.10.2026 18:26