# Researchers identify ASHVEIN malware targeting Ukrainian government personnel

_Published Thursday, October 8, 2026 at 11:36 AM EDT · Security · Latest · Tier 2 — Notable_

![Researchers identify ASHVEIN malware targeting Ukrainian government personnel — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZWPW7zD0DZUCKyeRcD-sBZtZ28n4PPaJDPjiskf9ghOI7b3aYbYCEbNvITxaYjCkejq8Vfuc0xeZtJ7p2R4j4dEqGXwfb1JLqQVHrgE4uxdSCq-JJgAeLA0WZbz5Fi98LQbxr3ncRXodrBd83xaX2UpXtDb-Q55ryWBPeXGAQlDBykN_BYecleld5rxJM/s1700-nu-rw-lo-l85-e365/uk.jpg)

TrendAI has identified previously undocumented ASHVEIN malware used against Ukrainian government personnel and attributed it to the Russia-aligned UAC-0099 group, The Hacker News reported. The tool combines browser credential theft, screenshots, file retrieval and remote PowerShell execution.

ASHVEIN hides commands in invisible HTML elements, and some variants use GitHub as a fallback for locating command infrastructure. Delivery methods include a program that displays a document impersonating Ukraine's National Police while installing malware. TrendAI says available evidence suggests targeting has expanded to civilian logistics and infrastructure operators.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/uac-0099-targets-ukrainian-government.html)

---
Canonical: https://techandbusiness.org/newswire/eVFj2M6YysH7mqP38h4Q2x
Published: 2026-10-08T15:36:37.369Z
Story chronology: 2026-10-08T15:26:56.000Z
Retrieved: 2026-10-08T17:33:58.850Z
Publisher: Tech & Business (techandbusiness.org)
