Security1 publisherNot yet confirmed elsewhere2 min readPublished
Invisible HTML elements carry the commands for UAC-0099's ASHVEIN RAT
TrendAI has tied ASHVEIN, a previously undocumented .NET RAT, to UAC-0099 attacks on Ukrainian government personnel, citing five builds from October 2025. The group has fielded newer tools since, so detection that lasts has to target how it delivers and tasks its implants.
The Watch · Security desk
What happened
- ASHVEIN steals Chrome and Firefox credentials, captures screenshots, enumerates and pulls files, runs a PowerShell remote shell and fingerprints hosts over encrypted command-and-control.
- One dropper, AnswerFromPolice, opens a Word document posing as a reply from the National Police of Ukraine while it installs the malware in the background.
- CERT-UA first documented UAC-0099 in June 2023, and the group has targeted Ukrainian government, defense, border guard and logistics entities since at least mid-2022.
- ESET said in its November 2025 APT Activity Report that UAC-0099 can act as an initial access broker for Sandworm.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Indicators from the October 2025 builds mostly help hunt past intrusions. Coverage that holds up against the group's newer tools has to key on DLL sideloading, VHD containers and commands read from HTML.
- capability The GitHub dead-drop fallback gives some variants a second path to their operators, so blocking the primary C2 server may not cut an infected host off.
- exposure If ESET's broker assessment holds, an ASHVEIN infection in a Ukrainian government network is a possible staging point for destructive Sandworm operations, and responders should scope it beyond espionage.
- precedent Separate developer accounts building overlapping stealers make further parallel tools from this group likely, and a signature written for one family cannot be assumed to catch another.
For detection work, the most useful part of TrendAI's write-up is how ASHVEIN gets its orders. "ASHVEIN also hides tasking inside invisible HTML elements," TrendAI said. "Some variants use a GitHub-based dead drop resolver as a fallback mechanism, while delivery methods include DLL sideloading, VHD containers, and dedicated .NET droppers." [4] The vendor tracks the sideloading chain as FORGECLAMP [5] and the cluster as Earth Sirrush, previously SHADOW-EARTH-065 [2]. Internally, the developers call the RAT "TelemetryBrowser" [16].
TrendAI said the police-themed decoy was chosen on purpose: "This combination of institutional impersonation and credible decoy content is designed to increase the likelihood that recipients will open and trust the file." [7]
ASHVEIN is newly documented, but the code dates from October 2025. "Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants," TrendAI said [8]. The group's malware timeline then lists BadPaw, also tracked as CINDERBLOT, and a backdoor called MeowMeow from February to April 2026 [9]. From April to July 2026 came LUNCHPOKE, a .NET DLL posing as a Notepad++ plugin, along with the BURNYBEAR loader and MATCHBOIL.V2 [10]. Five tools or versions followed ASHVEIN, the newest about nine months after its builds [19][20].
The arsenal has moved one way. UAC-0099 shifted from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries hidden in steganographic image files [11]. TrendAI also compared ASHVEIN with DRAGSTARE, a C# information stealer the group used in 2024 and 2025. The two overlap in credential theft, screenshots, file collection and WMI fingerprinting [17]. They were compiled under separate developer accounts with different packing [18]. "The functional overlap, combined with separate build environments, indicates parallel tool development under different developer accounts for the same operational requirement," TrendAI said [12].
The record conflicts on one point that matters for coverage. The Hacker News lists Chrome and Firefox credential theft among ASHVEIN's functions [3]. TrendAI's comparison, though, cites two-browser targeting as something that sets DRAGSTARE apart, saying it "targets both Chrome and Firefox, and includes anti-VM checks and subnet scanning" [13]. The published material does not settle whether ASHVEIN reads Firefox credential stores [21].
What to watch
- Whether TrendAI or CERT-UA publishes indicators for the HTML tasking format or the GitHub accounts used as dead drops.
- Whether ASHVEIN turns up in 2026 delivery chains alongside BURNYBEAR or MATCHBOIL.V2, which would show it is still in use.
- Any public case where Sandworm activity follows a UAC-0099 intrusion, which would confirm ESET's broker assessment in practice.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence50
- Adoption25
- Hype gap+10
- Incentives35
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The Russia-aligned threat actor UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan codenamed ASHVEIN.
- [2]
According to TrendAI, ASHVEIN has been used in attacks targeting Ukrainian government personnel; TrendAI tracks the cluster as Earth Sirrush (previously SHADOW-EARTH-065).
- [3]
ASHVEIN's functionality includes credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control communications.
- [4]
"ASHVEIN also hides tasking inside invisible HTML elements," TrendAI said. "Some variants use a GitHub-based dead drop resolver as a fallback mechanism, while delivery methods include DLL sideloading, VHD containers, and dedicated .NET droppers."
- [5]
UAC-0099 delivers ASHVEIN through DLL sideloading (aka FORGECLAMP), VHD containers, and purpose-built .NET droppers.
- [6]
One .NET dropper, AnswerFromPolice, embeds a Microsoft Word document purporting to be a response from the National Police of Ukraine and displays it as a decoy while deploying the malware in the background.
- [7]
"This combination of institutional impersonation and credible decoy content is designed to increase the likelihood that recipients will open and trust the file," TrendAI said.
- [8]
"Five builds were compiled between October 8 and October 23, 2025, across three distinct packing variants," TrendAI said.
- [9]
UAC-0099's malware timeline lists BadPaw aka CINDERBLOT (.NET-based loader) and MeowMeow (backdoor) in February to April 2026.
- [10]
UAC-0099's malware timeline lists LUNCHPOKE (.NET DLL that masquerades as a Notepad++ plugin), BURNYBEAR (.NET-based loader) and MATCHBOIL.V2 (updated version of MATCHBOIL) in April to July 2026.
- [11]
UAC-0099 has expanded its arsenal while shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files.
- [12]
"The functional overlap, combined with separate build environments, indicates parallel tool development under different developer accounts for the same operational requirement," TrendAI said.
- [13]
"DRAGSTARE was compiled by the NordDragon developer account, targets both Chrome and Firefox, and includes anti-VM checks and subnet scanning," TrendAI said, listing differences between DRAGSTARE and ASHVEIN.
- [14]
CERT-UA first documented UAC-0099 in June 2023; the group has targeted Ukrainian government, defense, border guard, and logistics entities since at least mid-2022.
- [15]
ESET, in its APT Activity Report published in November 2025, said UAC-0099 can serve as an initial access broker for Sandworm, a Russian APT group best known for destructive attacks against Ukraine.
- [16]
ASHVEIN's developers internally refer to it as "TelemetryBrowser".
- [17]
DRAGSTARE aka NordDragonScan, a C#-based information stealer in UAC-0099's 2024-2025 toolset, overlaps functionally with ASHVEIN in credential theft, screenshots, file collection, and WMI fingerprinting, according to TrendAI.
- [18]
According to TrendAI, DRAGSTARE was compiled by the NordDragon developer account, while ASHVEIN was compiled by the dev account and uses a different packing approach.
- [19]
Five tools or versions appear in UAC-0099's timeline after ASHVEIN: BadPaw, MeowMeow, LUNCHPOKE, BURNYBEAR and MATCHBOIL.V2.
- [20]
The newest tooling in the timeline (window ending July 2026) is about nine months younger than the ASHVEIN builds (October 2025).
- [21]
The source material is inconsistent on whether ASHVEIN targets Firefox: the capability list includes Firefox, while TrendAI's comparison presents Chrome-and-Firefox targeting as a DRAGSTARE differentiator.
Sources
1 independent publisher whose own reporting we read for this story.
- thehackernews.comUAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- InfostealersFollow
- Russian cyber operations against UkraineFollow
- DLL sideloading and signed-binary abuseFollow
- Remote Access TrojansFollow