Back
UAC-0099 Deploys ASHVEIN RAT Against Ukrainian Government Targets
SiTech AI Team3 min read

UAC-0099 Deploys ASHVEIN RAT Against Ukrainian Government Targets

Russia-aligned threat actor UAC-0099 has been linked to a new .NET infostealer and remote access trojan called ASHVEIN, used in attacks on Ukrainian government personnel.

Russia-aligned threat actor UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan codenamed ASHVEIN, according to TrendAI. The malware, internally referred to by its developers as "TelemetryBrowser," has been used in attacks targeting Ukrainian government personnel. TrendAI tracks the cluster under the name Earth Sirrush, previously known as SHADOW-EARTH-065.

ASHVEIN Capabilities and Delivery

ASHVEIN combines credential theft, surveillance, and remote-control functionality. Its capabilities include stealing credentials from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control communications. TrendAI noted that ASHVEIN hides tasking inside invisible HTML elements. Some variants use a GitHub-based dead drop resolver as a fallback mechanism.

Delivery methods include DLL sideloading, VHD containers, and dedicated .NET droppers. One such dropper, AnswerFromPolice, embeds a Microsoft Word document that purports to be a response from the National Police of Ukraine. The decoy document is displayed to the victim while the malware deploys in the background, a combination designed to increase the likelihood that recipients will open and trust the file.

Expanding Arsenal and Targeting

UAC-0099 was first documented by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2023 and has targeted Ukrainian government, defense, border guard, and logistics entities since at least mid-2022. ESET reported in November 2025 that the group can serve as an initial access broker for Sandworm, the Russian APT group known for destructive attacks against Ukraine.

Over the years, the actor has shifted from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files. Its arsenal has grown from LONEPAGE, THUMBCHOP, CLOGFLAG, SEAGLOW, and OVERJAM in 2022 to 2024, to MATCHBOIL, MATCHWOK, and DRAGSTARE in 2024 to 2025, and further to BadPaw, MeowMeow, LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2 in 2026.

TrendAI said five ASHVEIN builds were compiled between October 8 and October 23, 2025, across three distinct packing variants. The malware overlaps functionally with DRAGSTARE in credential theft, screenshots, file collection, and WMI fingerprinting, but the two were compiled under different developer accounts, indicating parallel tool development for the same operational requirement.

GuardBreaker AI Evasion Experiment

ESET also observed UAC-0099 using a technique called GuardBreaker against a Ukrainian target to undermine AI-assisted analysis. A malicious Visual Basic Script deployed by the adversary embedded a prompt asking for instructions to make a nuclear weapon, an attempt to deliberately trigger a large language model's safety mechanisms and prevent it from analyzing the rest of the code. The VBScript serves as a conduit for MATCHBOIL. However, evidence suggests this AI-based approach was a short-lived experiment, as the threat actor is no longer employing the tactic prior to malware deployment.

TrendAI said targeting has expanded beyond government and military organizations to include civilian logistics and infrastructure operators that keep Ukraine supplied. The shift tracks the war, as the value of understanding Ukraine's logistics networks rises and the cyber effort follows the same logic as the kinetic one.

Sources: The Hacker News

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.