VYPR
researchPublished Oct 8, 2026· 1 source

UAC-0099 Deploys ASHVEIN RAT to Target Ukrainian Government Personnel

Russia-aligned threat actor UAC-0099, also known as Earth Sirrush, is using a new .NET infostealer and RAT called ASHVEIN to target Ukrainian government employees, with commands cleverly hidden within HTML files.

The Russia-aligned threat actor UAC-0099, tracked by cybersecurity researchers as Earth Sirrush, has been observed deploying a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. This sophisticated malware, internally referred to by its developers as "TelemetryBrowser," is being used in targeted attacks against Ukrainian government personnel. The campaign underscores the persistent and evolving cyber threats directed at Ukrainian entities.

ASHVEIN consolidates a range of malicious functionalities, including credential theft from popular web browsers like Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, and the execution of PowerShell commands for remote shell access. It also performs system fingerprinting and utilizes encrypted command-and-control (C2) communications. A notable evasion technique employed by ASHVEIN is its ability to conceal tasking commands within invisible HTML elements, making detection more challenging for security solutions.

UAC-0099, first documented by Ukraine's Computer Emergency Response Team (CERT-UA) in June 2023, has a history of targeting Ukrainian government, defense, border guard, and logistics organizations since mid-2022. ESET's research has indicated that UAC-0099 may function as an initial access broker for the notorious Russian APT group Sandworm, known for its destructive cyber operations. Over time, the threat actor has expanded its malware arsenal, shifting from PowerShell and Go-based tools to compiled C# and .NET binaries, often protected by .NET Reactor and concealed within steganographic image files.

The malware's development timeline shows a consistent evolution, with ASHVEIN emerging in October 2025, following earlier tools like LONEPAGE and THUMBCHOP, and preceding later variants such as BadPaw and MeowMeow in early 2026. The threat actor has also developed other .NET-based tools like MATCHBOIL, MATCHWOK, and DRAGSTARE, indicating a strategic investment in diverse capabilities. ASHVEIN shares functional overlaps with DRAGSTARE, particularly in credential theft and data exfiltration, but distinct development environments and packing methods suggest parallel tool development efforts within the group.

Delivery methods for ASHVEIN are varied and sophisticated, including DLL sideloading, the use of VHD containers, and custom-built .NET droppers. One such dropper, named AnswerFromPolice, embeds a decoy Microsoft Word document impersonating a response from the National Police of Ukraine. This tactic aims to exploit the recipient's trust in official communications to facilitate malware deployment.

Further evolving its tradecraft, UAC-0099 has been observed using techniques like GuardBreaker to undermine AI-assisted analysis. A malicious VBScript has been found to embed prompts designed to trigger the safety mechanisms of large language models, preventing them from analyzing the script's true malicious payload. This demonstrates an awareness of and adaptation to emerging defensive technologies.

The targeting scope of UAC-0099 appears to be expanding beyond purely government and military entities to include civilian logistics and infrastructure operators. This shift aligns with the ongoing conflict, as understanding Ukraine's logistical networks becomes increasingly valuable, and cyber operations mirror kinetic strategies.

Recent activity also includes the evolution of the MATCHBOIL downloader, with new iterations appearing as DLL files executed by custom C# loaders. These versions incorporate anti-virtualization checks and other anti-analysis measures, highlighting the continuous effort by UAC-0099 to evade detection and maintain operational effectiveness.

Synthesized by Vypr AI