DKDKCISSPSearch
Threat ResearchDEVELOPING

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN .

DKCISSP News DeskThe Hacker News8 Oct 2026, 8:56 pm
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel.

The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN .

ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.

For an MSSP, a suspicious Wazza domain found while investigating one customer can also become a starting point for hunting related activity across other environments.

ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.

For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.

The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets.

An analyst can investigate a Wazza URL, identify useful indicators, validate them, and make that intelligence available to the systems monitoring customer environments.

In the intervening time period, the threat actor has steadily expanded its malware arsenal, while shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files.

Some of the malware families deployed by the threat actor over the years are listed below - "Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants," TrendAI said.

What happened

According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel.

The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN .

What changed

ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.

For an MSSP, a suspicious Wazza domain found while investigating one customer can also become a starting point for hunting related activity across other environments.

Who is affected

ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.

For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.

Why it matters

The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets.

An analyst can investigate a Wazza URL, identify useful indicators, validate them, and make that intelligence available to the systems monitoring customer environments.

Technical details

In the intervening time period, the threat actor has steadily expanded its malware arsenal, while shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files.

Some of the malware families deployed by the threat actor over the years are listed below - "Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants," TrendAI said.

AnswerFromPolice displays the decoy document impersonating the National Police of Ukraine while deploying the malware in the background.

Response

MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control.

The flow begins at a wildcard landing domain, [.]boegl-krysl[.]eu , where the visitor is passed to /api/wazza-config .

What security teams should do

That token is passed to check[.]boegl-krysl[.]eu , where Wazza validates the token and browser telemetry and filters unwanted traffic.

Blocking one Wazza domain does not necessarily end the campaign.

Attribution

The Hacker News: The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN .

The Hacker News: Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Microsoft Teams to get support for third-party deepfake detection toolsBleepingComputer · 8 Oct 2026, 5:38 pm16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery PhrasesThe Hacker News · 8 Oct 2026, 3:16 pmMicrosoft Outlook to block MSIX attachments starting NovemberBleepingComputer · 7 Oct 2026, 9:14 pmChina-Linked JDY Botnet Expands to 1,500+ Devices for Cyber ReconnaissanceThe Hacker News · 7 Oct 2026, 8:28 pm