The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN.
According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065).
ASHVEIN, which its developers internally refer to as “TelemetryBrowser,” brings together credential theft, surveillance, and remote-control capabilities. Its functionality includes credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control (C2) communications.
“ASHVEIN also hides tasking inside invisible HTML elements,” TrendAI said. “Some variants use a GitHub-based dead drop resolver as a fallback mechanism, while delivery methods include DLL sideloading, VHD containers, and dedicated .NET droppers.”
UAC-0099 was first documented by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2023. It has a history of targeting Ukrainian government, defense, border guard, and logistics entities since at least mid-2022, emerging in the wake of Russia’s full-scale invasion of Ukraine.
ESET, in its APT Activity Report published in November 2025, said the cyber espionage crew can serve as an initial access broker for Sandworm, a Russian advanced persistent threat (APT) group best known for its destructive attacks against Ukraine.
In the intervening time period, the threat actor has steadily expanded its malware arsenal, while shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files.
Some of the malware families deployed by the threat actor over the years are listed below –
“Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants,” TrendAI said. “ASHVEIN overlaps functionally with DRAGSTARE in credential theft, screenshots, file collection, and WMI fingerprinting, but key differences separate them.”
“DRAGSTARE was compiled by the NordDragon developer account, targets both Chrome and Firefox, and includes anti-VM checks and subnet scanning. ASHVEIN, compiled by the dev account, uses a different packing approach. The functional overlap, combined with separate build environments, indicates parallel tool development under different developer accounts for the same operational requirement.”
UAC-0099 makes use of multiple delivery methods for ASHVEIN, including DLL sideloading (aka FORGECLAMP), VHD containers, and purpose-built .NET droppers. One such .NET executable is AnswerFromPolice, which embeds a Microsoft Word document that purports to be a response from the National Police of Ukraine.
AnswerFromPolice displays the decoy document impersonating the National Police of Ukraine while deploying the malware in the background. “This combination of institutional impersonation and credible decoy content is designed to increase the likelihood that recipients will open and trust the file,” TrendAI said.
Another malware family that has undergone extensive evolution over the past year is MATCHBOIL. ESET’s research indicates that the C# downloader has been under active development since at least April 2024. MATCHBOIL’s primary responsibility is to download, install, and persist another payload.
Leave a Reply