Ukrainian government staff opened ordinary-looking HTML and handed an operator a desktop. TrendAI attributes a previously undocumented .NET infostealer and remote access trojan, ASHVEIN, to the Russia-aligned cluster UAC-0099, also tracked as Earth Sirrush. The malware hid commands in HTML that mail clients render without a second thought. That is a cybersecurity incident that starts in the inbox, before your firewall ever sees a suspicious packet.

You already allow HTML. Operators counted on that this week. They also ran event-themed Google session theft against people tied to Taiwan research organizations. Trusted content. Live access. Same week.

Inbox HTML Became a Government C2 Channel

ASHVEIN is a .NET package that steals and stays. An infostealer plus a RAT means credentials and tokens leave first, then an operator keeps the foothold for hands-on work. Hiding the command channel in HTML is the part that should bother you. Your users live in browsers and mail clients. Those clients parse HTML for a living. A document is a perfectly good C2 wrapper if your stack treats markup as a letter.

UAC-0099 went after Ukrainian government personnel. That’s a target set sitting on classified correspondence, wartime logistics, and humans clearing a queue under pressure. A flashy exploit is optional when the victim’s job is to open formatted messages from colleagues and ministries. HTML in that environment looks like work product. It is work product with an operator prompt folded in.

TrendAI reports a previously undocumented .NET infostealer and RAT, ASHVEIN, used against Ukrainian government personnel, with operator commands hidden in HTML.

Report on UAC-0099 ASHVEIN malware targeting Ukrainian government personnel
UAC-0099, also tracked as Earth Sirrush, used ASHVEIN to steal data and retain remote access on government desktops.

If your threat detection only lights up on classic beacons, packed executables, or noisy brute-force against VPN, this campaign walks around you. HTML looks like a newsletter. Follow-on traffic can hide in the same protocols your cyber security policy already blesses for browsers. Defense in depth fails when every layer agrees that HTML is content.

Score HTML from a plausible sender as high risk until you prove otherwise. Plausible is the point. Government and research mail is full of tables, letterhead, and forwarded briefs. ASHVEIN is built for that clutter. Your preview pane is part of the blast radius. Plenty of clients fetch remote resources when a message is selected. If you only coach users to avoid clicking, you are coaching the wrong moment. The render is the click.

Rendered Mail Is a Cybersecurity Execution Surface

If a renderer runs it, it is code. Do this work this week without waiting on a new product.

  • Immediate: quarantine inbound HTML and MHTML for government, research, and executive mailboxes. Deliver plain text plus a sandboxed preview. Hunt endpoints for new .NET persistence, unusual child processes from Outlook or the HTML host, and outbound sessions that start right after a render.
  • Immediate: revoke tokens and force reauthentication for anyone who followed a conference, academic, or policy-themed Google login. Adversary-in-the-middle phishing steals the session. A password reset that leaves cookies alive wastes the afternoon.
  • Immediate: patch the Cisco defects SecurityWeek describes as a dozen criticals covering unauthorized access, leaks, privilege escalation, denial of service, and remote code execution. Pull management interfaces off the internet so a stolen mailbox cannot walk into an unpatched appliance.
  • Ongoing: add an incident response branch for HTML-as-C2 and session theft. Detonate HTML at the gateway, not just hash attachments. Keep security hardening on egress, and put threat-protection on new devices, new ASNs, and lookalike event domains after a successful MFA.

Hunt like the HTML was a loader. Timeline the open. Pull the raw MIME. Extract every URL, iframe, form, and script. Then walk the endpoint. You want scheduled tasks, unexpected .NET loads, and browser helpers that appeared after the message landed.

Treat Google Workspace sessions as crown jewels. AitM kits sit between the user and the real login. MFA still fires. The attacker copies the cookie. Failed-password dashboards will stay green while the thief reads the mailbox.

Event Pages and Unpatched Gear Widen the Blast

Cisco Talos tracked UAT-11985 hitting people affiliated with Taiwan research organizations. Spear-phishing borrowed real public event themes. The lures impersonated academic and policy institutions you would not blink at on a Tuesday. AI helped the copy. The payload was real-time Google adversary-in-the-middle phishing. Live session. Live mail. Live drive.

Cisco Talos threat spotlight on AI-assisted event lure phishing
Talos says UAT-11985 used public event themes and academic impersonation to run live Google adversary-in-the-middle phishing.

The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions.

Research inboxes are built to RSVP. That reflex is the exploit. An event page with the right seals and a Google login feels like logistics, so people type. Session theft beats dropping a binary when the goal is mail and files. Pair that with a RAT in a ministry inbox and you have two ways to own the same class of target: steal the session, or hide in the HTML they already open.

Cisco’s latest critical batch is the boring half of the same week. Privilege and RCE on gear that sits next to identity is how a stolen cookie becomes a plant-wide problem. Management interfaces still hanging on the internet are an invitation. Watch those planes after any confirmed phish. If an attacker has a mailbox and an unpatched concentrator, they will combine them.

Your incident response playbook should assume they already did. Check for new admin users, unexpected tunnel configs, and configuration exports. Then lock admin paths to jump hosts you actually monitor. Research orgs and public-sector IT keep getting hit because the work is collaborative by design. Collaboration is a feature. Unreviewed HTML, unverified event logins, and internet-exposed appliance admin are choices you still own. Close those and these campaigns get expensive for the operator.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.