AnswerFromPolice is a Windows .NET malware dropper used by the Russia-aligned threat actor Earth Sirrush, also tracked as UAC-0099, in operations targeting Ukrainian organizations. The executable embeds and displays a Microsoft Word decoy purporting to be a response from the National Police of Ukraine while deploying malware in the background. This institutional impersonation is intended to encourage recipients to open and trust the executable while distracting them from payload deployment. AnswerFromPolice is associated with delivery of ASHVEIN, an information stealer and remote access trojan deployed against Ukrainian government personnel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AnswerFromPolice displays the decoy document impersonating the National Police of Ukraine while deploying the malware in the background.
Delivery component displaying a document impersonating the National Police of Ukraine while deploying malware.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Purpose-built .NET executable used to deliver ASHVEIN. It embeds and displays a Microsoft Word document purporting to be a response from the National Police of Ukraine while deploying the malware in the background.
Deploys malware while displaying a decoy document impersonating Ukraine's National Police.
Named malicious delivery component that displays a document impersonating Ukraine's National Police while deploying malware. Its payload and technical implementation are not specified.
An ASHVEIN delivery component that displays a National Police of Ukraine-themed decoy document while deploying the malware in the background.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.