The Russia-aligned threat actor UAC-0099 has been linked to a previously undocumented .NET infostealer and remote access trojan (RAT) named ASHVEIN. Cybersecurity firm TrendAI is tracking this activity, which targets Ukrainian government personnel, under the name Earth Sirrush.
ASHVEIN, internally referred to as "TelemetryBrowser" by its developers, integrates credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control (C2) communications. A notable feature is its ability to hide tasking within invisible HTML elements. Some variants also use a GitHub-based dead drop resolver as a fallback mechanism.
Delivery methods for ASHVEIN include DLL sideloading, VHD containers, and dedicated .NET droppers. UAC-0099 was first documented by CERT-UA in June 2023 and has consistently targeted Ukrainian government, defense, border guard, and logistics entities since mid-2022. ESET's November 2025 APT Activity Report indicated that UAC-0099 may act as an initial access broker for Sandworm, a Russian APT group known for destructive attacks against Ukraine.
UAC-0099 has expanded its malware arsenal, transitioning from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries often concealed within steganographic image files. Their historical malware families include LONEPAGE, THUMBCHOP, CLOGFLAG, SEAGLOW, OVERJAM (2022-2024), MATCHBOIL, MATCHWOK, DRAGSTARE (2024-2025), ASHVEIN (October 2025), BadPaw, MeowMeow (February-April 2026), LUNCHPOKE, and BURNYBEAR (April-July 2026).
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Russia-aligned threat actor UAC-0099 is using a new .NET infostealer and remote access trojan (RAT) called ASHVEIN in attacks against Ukrainian government personnel. ASHVEIN combines credential theft, surveillance, and remote-control capabilities, hiding commands within invisible HTML elements.