UAC-0099 Deploys ASHVEIN RAT Against Ukrainian Government via HTML Smuggling
Russia-aligned threat actor uses hidden commands in HTML files to deliver .NET-based remote access trojan

Key Takeaways
- UAC-0099 (Earth Sirrush) targets Ukrainian government personnel with the ASHVEIN .NET RAT/infostealer.
- HTML smuggling is used to deliver the malware, concealing commands within HTML files to evade detection.
- No patch is available; mitigation focuses on user awareness, email security, and endpoint monitoring for ASHVEIN behaviors.
Quick answers
Related Security News

FBI Arrests Suspected ShinyHunters Member Following Agency System Breach
The FBI arrested a suspect believed to be a member of the ShinyHunters extortion group, who is alleged to be involved in a recent breach of FBI systems. Director Kash Patel confirmed the arrest on Friday, marking a continued law enforcement effort to disrupt the group's operations.

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild to Deploy Webshells and Cryptominers
Threat actors are exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform. One vulnerability is rated critical severity and another medium severity. The exploitation has been observed in the wild and is being used to deploy webshells for persistent access and cryptocurrency miners for monetization. No patches are currently available, and the vulnerabilities remain unpatched. Affected organizations using AhsayCBS for backup management are at risk of persistent compromise and resource misuse.



