← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

UAC-0099 Targets Ukrainian Government with New ASHVEIN RAT

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • UAC-0099 uses ASHVEIN, a new .NET infostealer/RAT.
  • ASHVEIN targets Ukrainian government personnel.
  • Malware performs credential theft, surveillance, and remote control.
  • Commands are hidden in invisible HTML elements.

New Malware ASHVEIN Discovered

The Russia-aligned threat actor UAC-0099 has been linked to a previously undocumented .NET infostealer and remote access trojan (RAT) named ASHVEIN. Cybersecurity firm TrendAI is tracking this activity, which targets Ukrainian government personnel, under the name Earth Sirrush.

ASHVEIN's Capabilities

ASHVEIN, internally referred to as "TelemetryBrowser" by its developers, integrates credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control (C2) communications. A notable feature is its ability to hide tasking within invisible HTML elements. Some variants also use a GitHub-based dead drop resolver as a fallback mechanism.

Delivery Methods and Actor Background

Delivery methods for ASHVEIN include DLL sideloading, VHD containers, and dedicated .NET droppers. UAC-0099 was first documented by CERT-UA in June 2023 and has consistently targeted Ukrainian government, defense, border guard, and logistics entities since mid-2022. ESET's November 2025 APT Activity Report indicated that UAC-0099 may act as an initial access broker for Sandworm, a Russian APT group known for destructive attacks against Ukraine.

Evolving Malware Arsenal

UAC-0099 has expanded its malware arsenal, transitioning from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries often concealed within steganographic image files. Their historical malware families include LONEPAGE, THUMBCHOP, CLOGFLAG, SEAGLOW, OVERJAM (2022-2024), MATCHBOIL, MATCHWOK, DRAGSTARE (2024-2025), ASHVEIN (October 2025), BadPaw, MeowMeow (February-April 2026), LUNCHPOKE, and BURNYBEAR (April-July 2026).

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Russia-aligned threat actor UAC-0099 is using a new .NET infostealer and remote access trojan (RAT) called ASHVEIN in attacks against Ukrainian government personnel. ASHVEIN combines credential theft, surveillance, and remote-control capabilities, hiding commands within invisible HTML elements.