UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN .

According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel.
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN .
ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.
For an MSSP, a suspicious Wazza domain found while investigating one customer can also become a starting point for hunting related activity across other environments.
ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.
For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.
The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets.
An analyst can investigate a Wazza URL, identify useful indicators, validate them, and make that intelligence available to the systems monitoring customer environments.
In the intervening time period, the threat actor has steadily expanded its malware arsenal, while shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files.
Some of the malware families deployed by the threat actor over the years are listed below - "Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants," TrendAI said.
What happened
According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel.
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN .
What changed
ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.
For an MSSP, a suspicious Wazza domain found while investigating one customer can also become a starting point for hunting related activity across other environments.
Who is affected
ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.
For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.
Why it matters
The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets.
An analyst can investigate a Wazza URL, identify useful indicators, validate them, and make that intelligence available to the systems monitoring customer environments.
Technical details
In the intervening time period, the threat actor has steadily expanded its malware arsenal, while shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files.
Some of the malware families deployed by the threat actor over the years are listed below - "Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants," TrendAI said.
AnswerFromPolice displays the decoy document impersonating the National Police of Ukraine while deploying the malware in the background.
Response
MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control.
The flow begins at a wildcard landing domain, [.]boegl-krysl[.]eu , where the visitor is passed to /api/wazza-config .
What security teams should do
That token is passed to check[.]boegl-krysl[.]eu , where Wazza validates the token and browser telemetry and filters unwanted traffic.
Blocking one Wazza domain does not necessarily end the campaign.
Attribution
The Hacker News: The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN .
The Hacker News: Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.