Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Crypto Projects Seek Anthropic AI Security Scans

    October 9, 2026

    British households would be £5,000 richer if we were more innovative. Let’s unleash our talents | Gordon Brown

    October 9, 2026

    Families reunited as USS Lincoln comes home after record 9-month deployment

    October 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Crypto Projects Seek Anthropic AI Security Scans
    • British households would be £5,000 richer if we were more innovative. Let’s unleash our talents | Gordon Brown
    • Families reunited as USS Lincoln comes home after record 9-month deployment
    • Zack Polanski faces greatest crisis of his leadership so far
    • Microsoft’s new Windows Search is exactly what Windows 11 needs
    • UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
    • Google Wants Gemini to Be Your Next Coworker—Complete With Its Own Email Address
    • Floodwaters Overwhelm Thailand – NASA Science
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN.

    According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065).

    ASHVEIN, which its developers internally refer to as “TelemetryBrowser,” brings together credential theft, surveillance, and remote-control capabilities. Its functionality includes credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control (C2) communications.

    “ASHVEIN also hides tasking inside invisible HTML elements,” TrendAI said. “Some variants use a GitHub-based dead drop resolver as a fallback mechanism, while delivery methods include DLL sideloading, VHD containers, and dedicated .NET droppers.”

    UAC-0099 was first documented by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2023. It has a history of targeting Ukrainian government, defense, border guard, and logistics entities since at least mid-2022, emerging in the wake of Russia’s full-scale invasion of Ukraine.

    ESET, in its APT Activity Report published in November 2025, said the cyber espionage crew can serve as an initial access broker for Sandworm, a Russian advanced persistent threat (APT) group best known for its destructive attacks against Ukraine.

    Cybersecurity

    In the intervening time period, the threat actor has steadily expanded its malware arsenal, while shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files.

    Some of the malware families deployed by the threat actor over the years are listed below –

    • 2022 – 2024: LONEPAGE (PowerShell-based loader), THUMBCHOP (C#-based browser stealer), CLOGFLAG (keylogger), SEAGLOW, and OVERJAM (Go-based backdoors for interactive access and reverse-proxy, respectively)
    • 2024 – 2025: MATCHBOIL (C#-based loader), MATCHWOK (C#-based backdoor), and DRAGSTARE aka NordDragonScan (C#-based information stealer)
    • October 2025: ASHVEIN aka TelemetryBrowser
    • February – April 2026: BadPaw aka CINDERBLOT (.NET-based loader) and MeowMeow (backdoor)
    • April – July 2026: LUNCHPOKE (.NET DLL that masquerades as a Notepad++ plugin), BURNYBEAR (.NET-based loader), and MATCHBOIL.V2 (updated version of MATCHBOIL)

    “Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants,” TrendAI said. “ASHVEIN overlaps functionally with DRAGSTARE in credential theft, screenshots, file collection, and WMI fingerprinting, but key differences separate them.”

    “DRAGSTARE was compiled by the NordDragon developer account, targets both Chrome and Firefox, and includes anti-VM checks and subnet scanning. ASHVEIN, compiled by the dev account, uses a different packing approach. The functional overlap, combined with separate build environments, indicates parallel tool development under different developer accounts for the same operational requirement.”

    UAC-0099 makes use of multiple delivery methods for ASHVEIN, including DLL sideloading (aka FORGECLAMP), VHD containers, and purpose-built .NET droppers. One such .NET executable is AnswerFromPolice, which embeds a Microsoft Word document that purports to be a response from the National Police of Ukraine.

    AnswerFromPolice displays the decoy document impersonating the National Police of Ukraine while deploying the malware in the background. “This combination of institutional impersonation and credible decoy content is designed to increase the likelihood that recipients will open and trust the file,” TrendAI said.

    Another malware family that has undergone extensive evolution over the past year is MATCHBOIL. ESET’s research indicates that the C# downloader has been under active development since at least April 2024. MATCHBOIL’s primary responsibility is to download, install, and persist another payload.

    Cybersecurity

    Recently observed iterations of MATCHBOIL have taken the form of a DLL file that’s executed by a custom C# loader. The malware also checks to determine if it’s running in a virtual environment and aborts execution if the installation date of the operating system is 10 or more days older than the date on which the artifact is being executed.

    “This demonstrates a keen interest by UAC-0099 operators in improving their downloader, not only to avoid detection by security solutions, but also to use it as a key part of their toolset in future attacks,” ESET researcher Fernando Tavella said in a report shared with The Hacker News.

    In what appears to be yet another evolution of the threat actor’s tradecraft, the Slovak cybersecurity company said it observed the use of a technique called GuardBreaker against a Ukrainian target to undermine artificial intelligence (AI)-assisted analysis.

    Specifically, a malicious Visual Basic Script (VBScript) deployed by the adversary has been found to embed a prompt asking for instructions to make a nuclear weapon in an attempt to deliberately trigger a large language model’s (LLM) safety mechanisms and prevent it from analyzing the rest of the code. The VBScript serves as a conduit for MATCHBOIL.

    However, current visibility evidence indicates that this AI-based approach may have been a short-lived experiment, for Tavella told The Hacker News that the threat actor is no longer employing this tactic prior to the deployment of the malware.

    “Available evidence suggests that the targeting has expanded beyond government and military organizations to include civilian logistics and infrastructure operators that keep Ukraine supplied,” TrendAI said. “That drift tracks the war: As the conflict continues, the value of understanding Ukraine’s logistics networks rises, and the cyber effort follows the same logic as the kinetic one.”

    ASHVEIN Commands government Hiding HTML personnel RAT targets UAC0099 Ukrainian
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Low-cost Android phones ship with residential proxy malware

    Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

    ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

    FBI disrupts Chinese hacking tools used to breach critical infrastructure

    Oracle Health Data Breach Tally Climbs to Nearly 20 Million

    SonicWall and Splunk Patch Critical Vulnerabilities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Crypto Projects Seek Anthropic AI Security Scans

    October 9, 2026

    British households would be £5,000 richer if we were more innovative. Let’s unleash our talents | Gordon Brown

    October 9, 2026

    Families reunited as USS Lincoln comes home after record 9-month deployment

    October 9, 2026

    Zack Polanski faces greatest crisis of his leadership so far

    October 9, 2026
    Latest Posts

    Wisconsin’s partisan primary election is Tuesday. Learn more about who’s on your ballot.

    August 10, 2026

    Gabon ends fisheries partnership agreement with EU

    August 10, 2026

    Science backs calls for limiting screens in schools

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Crypto Projects Seek Anthropic AI Security Scans

    October 9, 2026

    British households would be £5,000 richer if we were more innovative. Let’s unleash our talents | Gordon Brown

    October 9, 2026

    Families reunited as USS Lincoln comes home after record 9-month deployment

    October 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.