
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN.
According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065).
ASHVEIN, which its developers internally refer to as "TelemetryBrowser," brings together credential theft, surveillance, and remote-control capabilities. Its functionality includes credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control (C2) communications.
"ASHVEIN also hides tasking inside invisible HTML elements," TrendAI said. "Some variants use a GitHub-based dead drop resolver as a fallback mechanism, while delivery methods include DLL sideloading, VHD containers, and dedicated .NET droppers."
UAC-0099 was first documented by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2023. It has a history of targeting Ukrainian government, defense, border guard, and logistics entities since at least mid-2022, emerging in the wake of Russia's full-scale invasion of Ukraine.
ESET, in its APT Activity Report published in November 2025, said the cyber espionage crew can serve as an initial access broker for Sandworm, a Russian advanced persistent threat (APT) group best known for its destructive attacks against Ukraine.
In the intervening time period, the threat actor has steadily expanded its malware arsenal, while shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files.
Some of the malware families deployed by the threat actor over the years are listed below -
- 2022 - 2024: LONEPAGE (PowerShell-based loader), THUMBCHOP (C#-based browser stealer), CLOGFLAG (keylogger), SEAGLOW, and OVERJAM (Go-based backdoors for interactive access and reverse-proxy, respectively)
- 2024 – 2025: MATCHBOIL (C#-based loader), MATCHWOK (C#-based backdoor), and DRAGSTARE aka NordDragonScan (C#-based information stealer)
- October 2025: ASHVEIN aka TelemetryBrowser
- February – April 2026: BadPaw aka CINDERBLOT (.NET-based loader) and MeowMeow (backdoor)
- April – July 2026: LUNCHPOKE (.NET DLL that masquerades as a Notepad++ plugin), BURNYBEAR (.NET-based loader), and MATCHBOIL.V2 (updated version of MATCHBOIL)
"Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants," TrendAI said. "ASHVEIN overlaps functionally with DRAGSTARE in credential theft, screenshots, file collection, and WMI fingerprinting, but key differences separate them."
"DRAGSTARE was compiled by the NordDragon developer account, targets both Chrome and Firefox, and includes anti-VM checks and subnet scanning. ASHVEIN, compiled by the dev account, uses a different packing approach. The functional overlap, combined with separate build environments, indicates parallel tool development under different developer accounts for the same operational requirement."
UAC-0099 makes use of multiple delivery methods for ASHVEIN, including DLL sideloading (aka FORGECLAMP), VHD containers, and purpose-built .NET droppers. One such .NET executable is AnswerFromPolice, which embeds a Microsoft Word document that purports to be a response from the National Police of Ukraine.
AnswerFromPolice displays the decoy document impersonating the National Police of Ukraine while deploying the malware in the background. "This combination of institutional impersonation and credible decoy content is designed to increase the likelihood that recipients will open and trust the file," TrendAI said.
Another malware family that has undergone extensive evolution over the past year is MATCHBOIL. ESET's research indicates that the C# downloader has been under active development since at least April 2024. MATCHBOIL's primary responsibility is to download, install, and persist another payload.
Recently observed iterations of MATCHBOIL have taken the form of a DLL file that's executed by a custom C# loader. The malware also checks to determine if it's running in a virtual environment and aborts execution if the installation date of the operating system is 10 or more days older than the date on which the artifact is being executed.
"This demonstrates a keen interest by UAC-0099 operators in improving their downloader, not only to avoid detection by security solutions, but also to use it as a key part of their toolset in future attacks," ESET researcher Fernando Tavella said in a report shared with The Hacker News.
In what appears to be yet another evolution of the threat actor's tradecraft, the Slovak cybersecurity company said it observed the use of a technique called GuardBreaker against a Ukrainian target to undermine artificial intelligence (AI)-assisted analysis.
Specifically, a malicious Visual Basic Script (VBScript) deployed by the adversary has been found to embed a prompt asking for instructions to make a nuclear weapon in an attempt to deliberately trigger a large language model's (LLM) safety mechanisms and prevent it from analyzing the rest of the code. The VBScript serves as a conduit for MATCHBOIL.
"Available evidence suggests that the targeting has expanded beyond government and military organizations to include civilian logistics and infrastructure operators that keep Ukraine supplied," TrendAI said. "That drift tracks the war: As the conflict continues, the value of understanding Ukraine's logistics networks rises, and the cyber effort follows the same logic as the kinetic one."