Find notable cyber news and cases, enriched with sources, timelines, and signals.

UAC-0099 campaign targeting Ukrainian government, logistics, and infrastructure entities

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The UAC-0099 campaign is now tied to a broader targeting set in Ukraine, including civilian logistics and infrastructure operators, which raises the risk to the systems that keep supply lines running. The operation has targeted government, defense, border guard, and logistics entities since at least mid-2022. It has also used ASHVEIN to collect credentials, capture screenshots, and open remote shells on victim systems. The actor's evolving tooling and widening victim set point to a persistent espionage operation with growing strategic reach.

Related Happenings

ASHVEIN (TelemetryBrowser) .NET infostealer and RAT activity against Ukrainian government personnel

Malware Activity
H score29 First: 08.10.2026 18:26 Last: 08.10.2026 18:26 Sources 1

How related: According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel.

About this happening: The ASHVEIN (TelemetryBrowser) malware activity now includes confirmed attacks against Ukrainian government personnel, giving UAC-0099 a new .NET infostealer/RAT f...

GTG-30006 Claude-assisted malware and phishing pipeline

Malware Activity
H score20 First: 11.09.2026 17:29 Last: 11.09.2026 17:29 Sources 1

About this happening: An Iranian actor, GTG-30006, used Claude.ai to build malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, increasing the risk of ...

Sandworm fake recruiter campaign targeting Ukrainian IT workers

Campaign
H score32 First: 11.08.2026 21:36 Last: 11.08.2026 21:36 Sources 1

About this happening: CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine si...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

Timeline

  1. 08.10.2026 18:26 2 articles · 6h ago

    UAC-0099 deploys ASHVEIN against Ukrainian government personnel and logistics operators

    Initial Disclosure

    UAC-0099, also tracked as Earth Sirrush and SHADOW-EARTH-065, is tied to ASHVEIN/TelemetryBrowser, a .NET infostealer and RAT used against Ukrainian government personnel. The campaign has targeted Ukrainian government, defense, border guard, logistics, and civilian logistics and infrastructure operators since at least mid-2022, and ASHVEIN steals credentials from Chrome and Firefox, captures screenshots, enumerates and retrieves files, runs PowerShell remote shells, hides tasking inside invisible HTML elements, and is delivered through DLL sideloading, VHD containers, and purpose-built .NET droppers.

    Show sources