Back to Feed
MalwareOct 8, 2026

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

Russia-aligned UAC-0099 uses new ASHVEIN RAT to target Ukrainian government personnel.

Summary

The Russia-aligned threat actor UAC-0099, also known as Earth Sirrush, is using a new .NET infostealer and RAT called ASHVEIN to target Ukrainian government personnel. ASHVEIN, internally referred to as 'TelemetryBrowser,' offers credential theft, surveillance, and remote control capabilities, with commands hidden in HTML elements. Delivery methods include DLL sideloading, VHD containers, and .NET droppers, often using institutional impersonation.

Full text

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML Ravie LakshmananOct 08, 2026Malware / Cyber Espionage The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN, which its developers internally refer to as "TelemetryBrowser," brings together credential theft, surveillance, and remote-control capabilities. Its functionality includes credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control (C2) communications. "ASHVEIN also hides tasking inside invisible HTML elements," TrendAI said. "Some variants use a GitHub-based dead drop resolver as a fallback mechanism, while delivery methods include DLL sideloading, VHD containers, and dedicated .NET droppers." UAC-0099 was first documented by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2023. It has a history of targeting Ukrainian government, defense, border guard, and logistics entities since at least mid-2022, emerging in the wake of Russia's full-scale invasion of Ukraine. ESET, in its APT Activity Report published in November 2025, said the cyber espionage crew can serve as an initial access broker for Sandworm, a Russian advanced persistent threat (APT) group best known for its destructive attacks against Ukraine. In the intervening time period, the threat actor has steadily expanded its malware arsenal, while shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files. Some of the malware families deployed by the threat actor over the years are listed below - 2022 – 2024: LONEPAGE (PowerShell-based loader), THUMBCHOP (C#-based browser stealer), CLOGFLAG (keylogger), SEAGLOW, and OVERJAM (Go-based backdoors for interactive access and reverse-proxy, respectively) 2024 – 2025: MATCHBOIL (C#-based loader), MATCHWOK (C#-based backdoor), and DRAGSTARE aka NordDragonScan (C#-based information stealer) October 2025: ASHVEIN aka TelemetryBrowser February – April 2026: BadPaw aka CINDERBLOT (.NET-based loader) and MeowMeow (backdoor) April – July 2026: LUNCHPOKE (.NET DLL that masquerades as a Notepad++ plugin), BURNYBEAR (.NET-based loader), and MATCHBOIL.V2 (updated version of MATCHBOIL) "Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants," TrendAI said. "ASHVEIN overlaps functionally with DRAGSTARE in credential theft, screenshots, file collection, and WMI fingerprinting, but key differences separate them." "DRAGSTARE was compiled by the NordDragon developer account, targets both Chrome and Firefox, and includes anti-VM checks and subnet scanning. ASHVEIN, compiled by the dev account, uses a different packing approach. The functional overlap, combined with separate build environments, indicates parallel tool development under different developer accounts for the same operational requirement." UAC-0099 makes use of multiple delivery methods for ASHVEIN, including DLL sideloading (aka FORGECLAMP), VHD containers, and purpose-built .NET droppers. One such .NET executable is AnswerFromPolice, which embeds a Microsoft Word document that purports to be a response from the National Police of Ukraine. AnswerFromPolice displays the decoy document impersonating the National Police of Ukraine while deploying the malware in the background. "This combination of institutional impersonation and credible decoy content is designed to increase the likelihood that recipients will open and trust the file," TrendAI said. Another malware family that has undergone extensive evolution over the past year is MATCHBOIL. ESET's research indicates that the C# downloader has been under active development since at least April 2024. MATCHBOIL's primary responsibility is to download, install, and persist another payload. Recently observed iterations of MATCHBOIL have taken the form of a DLL file that's executed by a custom C# loader. The malware also checks to determine if it's running in a virtual environment and aborts execution if the installation date of the operating system is 10 or more days older than the date on which the artifact is being executed. "This demonstrates a keen interest by UAC-0099 operators in improving their downloader, not only to avoid detection by security solutions, but also to use it as a key part of their toolset in future attacks," ESET researcher Fernando Tavella said in a report shared with The Hacker News. In what appears to be yet another evolution of the threat actor's tradecraft, the Slovak cybersecurity company said it observed the use of a technique called GuardBreaker against a Ukrainian target to undermine artificial intelligence (AI)-assisted analysis. Specifically, a malicious Visual Basic Script (VBScript) deployed by the adversary has been found to embed a prompt asking for instructions to make a nuclear weapon in an attempt to deliberately trigger a large language model's (LLM) safety mechanisms and prevent it from analyzing the rest of the code. The VBScript serves as a conduit for MATCHBOIL. However, current visibility evidence indicates that this AI-based approach may have been a short-lived experiment, for Tavella told The Hacker News that the threat actor is no longer employing this tactic prior to the deployment of the malware. "Available evidence suggests that the targeting has expanded beyond government and military organizations to include civilian logistics and infrastructure operators that keep Ukraine supplied," TrendAI said. "That drift tracks the war: As the conflict continues, the value of understanding Ukraine's logistics networks rises, and the cyber effort follows the same logic as the kinetic one." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, cyber espionage, Malware ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Wri

Indicators of Compromise

  • malware — ASHVEIN
  • malware — TelemetryBrowser
  • malware — LONEPAGE
  • malware — THUMBCHOP
  • malware — CLOGFLAG
  • malware — SEAGLOW
  • malware — OVERJAM
  • malware — MATCHBOIL
  • malware — MATCHWOK
  • malware — DRAGSTARE
  • malware — NordDragonScan
  • malware — BadPaw
  • malware — CINDERBLOT
  • malware — MeowMeow
  • malware — LUNCHPOKE
  • malware — BURNYBEAR
  • malware — FORGECLAMP
  • malware — AnswerFromPolice

Entities

UAC-0099 (threat_actor)Earth Sirrush (threat_actor)SHADOW-EARTH-065 (threat_actor)Sandworm (threat_actor)ASHVEIN (product)TelemetryBrowser (product)