Introduction

The Russia-aligned threat actor UAC-0099 has been linked to a new .NET-based infostealer and remote access trojan (RAT) called ASHVEIN, according to a report by TrendAI (formerly Trend Micro). The malware is being used in targeted attacks against Ukrainian government personnel, marking a continued espionage campaign against the region. TrendAI tracks the cluster as Earth Sirrush, previously known as SHADOW-EARTH-065.

Who is UAC-0099?

UAC-0099 is a threat group associated with Russian interests, known for its focus on Ukrainian targets. The group has historically employed phishing and malware to steal sensitive information from government and military entities. Their operations align with broader Russian cyber espionage efforts aimed at compromising Ukrainian state infrastructure.

ASHVEIN: A Stealthy .NET RAT

ASHVEIN is a previously undocumented malware family written in .NET. It combines infostealer and RAT functionalities, allowing attackers to exfiltrate data and maintain persistent remote access. Key capabilities include:

  • Command execution: Running arbitrary commands on compromised hosts.
  • File exfiltration: Stealing documents and other files.
  • Credential harvesting: Collecting login credentials from browsers and other applications.
  • Persistence: Ensuring the malware survives reboots.

The malware's use of .NET makes it portable and relatively easy to obfuscate, complicating detection.

HTML Smuggling: The Delivery Mechanism

ASHVEIN is delivered via HTML smuggling, a technique that hides malicious payloads within seemingly benign HTML attachments or web pages. When a victim opens the HTML file, JavaScript extracts and assembles the malware on the fly, bypassing network-based security controls that might block direct executable downloads. This method is effective because the malicious code is not present as a standalone file until it reaches the endpoint.

In this campaign, Ukrainian government personnel likely received spear-phishing emails containing HTML attachments or links. Once opened, the HTML file triggered the download and execution of ASHVEIN.

Targeting Ukrainian Government Personnel

The attacks specifically target Ukrainian government personnel, indicating a strategic focus on intelligence gathering. The stolen information could include sensitive communications, operational plans, and credentials that provide further access to government networks. This aligns with Russia's ongoing cyber operations against Ukraine.

Attribution and TrendAI's Analysis

TrendAI attributes the campaign to UAC-0099 with high confidence, based on infrastructure overlaps, tactics, techniques, and procedures (TTPs), and malware code similarities. The cluster Earth Sirrush has been active since at least 2022, consistently targeting Ukrainian entities. The introduction of ASHVEIN demonstrates the group's continued evolution and investment in custom tooling.

Implications and Recommendations

The use of HTML smuggling and a custom .NET RAT highlights the need for robust email security and endpoint detection. Organizations, especially those in government and critical infrastructure, should:

  • Educate users about phishing and suspicious attachments.
  • Implement advanced email filtering to detect HTML smuggling.
  • Deploy endpoint detection and response (EDR) solutions capable of identifying malicious .NET behavior.
  • Monitor for indicators of compromise associated with ASHVEIN and UAC-0099.
  • Apply network segmentation to limit lateral movement.

Conclusion

The UAC-0099 campaign using ASHVEIN underscores the persistent threat to Ukrainian government entities. As threat actors continue to refine their techniques, staying informed and adopting layered defenses is crucial. The original report by The Hacker News provides further technical details and indicators.

Source: The Hacker News