TrendAI said it found a new spy tool aimed at Ukrainian government staff. It named the tool ASHVEIN. Its makers call it "TelemetryBrowser". TrendAI ties it to a Russia-aligned group it tracks as Earth Sirrush, which overlaps with UAC-0099, a name used by Ukraine's CERT-UA. ASHVEIN is a remote access trojan, a program that lets attackers control a computer. TrendAI said it steals credentials from Chrome and Firefox. It also hides its orders in invisible HTML, the code behind web pages. The Hacker News, reporting on 8 October, added screenshots, file theft and a remote PowerShell shell. TrendAI said one dropper, AnswerFromPolice, shows a fake National Police of Ukraine document while it installs the malware.
TrendAI said no single clue proves the campaigns are linked. Together, though, the clues support its high-confidence view that one group is behind them. It says the group has been active since at least 2022. The Hacker News, citing TrendAI, reported five ASHVEIN builds made between 8 and 23 October 2025. The sources do not say how many people were hit, which agencies were affected, or what was stolen. ESET separately judged that UAC-0099 might gain first access for Sandworm, a Russian group known for destructive attacks on Ukraine.
TrendAI says the group keeps swapping its malware but leaves repeat habits that tie its campaigns together. For security teams, it advises watching for programs created in C:\Users\Public\Libraries\ and for renamed copies of schtasks.exe, a Windows tool that schedules tasks.