Mazda CX5
Як зробити цифрову копію себе. Ось відео —>

Russian hackers are attacking Ukrainians with a new Trojan, ASHVEIN, that hides commands in HTML. Targets range from government structures to civilian logistics

The Russian-linked hacker group UAC-0099 has developed a new malware, a spyware and remote access virus (RAT) called ASHVEIN (internal name TelemetryBrowser).

Leave a comment
Russian hackers are attacking Ukrainians with a new Trojan, ASHVEIN, that hides commands in HTML. Targets range from government structures to civilian logistics

The Russian-linked hacker group UAC-0099 has developed a new malware, a spyware and remote access virus (RAT) called ASHVEIN (internal name TelemetryBrowser).

This is reported by cybersecurity researchers at TrendAI.

The main targets of the attacks were Ukrainian civil servants, military personnel, border guards, as well as logistics companies that provide supplies in the country.

ASHVEIN is a complex spyware tool that allows attackers to take complete control of an infected computer, writes The Hacker News.

The virus reads saved credentials from Chrome and Firefox browsers, silently takes screenshots and collects system information. It also finds and transfers documents and files from the device to hackers, allowing them to execute command scripts (PowerShell) and gain full control over the PC.

A special feature of ASHVEIN is that it hides commands for execution inside transparent (invisible) HTML code elements, and also uses encrypted communication channels with its servers.

Hackers use phishing and manipulation to infect computers. In particular, they send a file called AnswerFromPolice.

When opening this file, the user is shown a fake document that mimics an official response from the National Police of Ukraine. While the victim reads the text, the ASHVEIN malware is secretly installed in the background.

According to ESET, the UAC-0099 group has been operating since at least mid-2022 and often acts as a “gateway” (primary access provider) for the more dangerous Russian hacking unit Sandworm, known for its devastating cyberattacks on Ukrainian infrastructure.

Analysts note that UAC-0099 is constantly updating its arsenal, and the expansion of targets from government structures to civilian logistics indicates the enemy's attempts to disrupt supply chains in Ukraine.

Hackers massively attack Hikvision cameras in Ukraine due to critical vulnerability
Hackers massively attack Hikvision cameras in Ukraine due to critical vulnerability
On the topic
Hackers massively attack Hikvision cameras in Ukraine due to critical vulnerability
Hackers tried to hack ATB website: what the company said
Hackers tried to hack ATB website: what the company said
On the topic
Hackers tried to hack ATB website: what the company said
Hackers steal data through fake "I'm not a robot" verification. CERT-UA detects large-scale cyberattack
Hackers steal data through fake "I'm not a robot" verification. CERT-UA detects large-scale cyberattack
On the topic
Hackers steal data through fake "I'm not a robot" verification. CERT-UA detects large-scale cyberattack
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.