ASHVEIN RAT campaign targets Ukrainian government personnel

Russia-aligned threat actor UAC-0099 has used a previously undocumented .NET information stealer and remote access trojan, ASHVEIN, in attacks targeting Ukrainian government personnel. TrendAI, which tracks the cluster as Earth Sirrush, said the malware combines credential theft, surveillance and remote-control functions.
ASHVEIN is internally referred to by its developers as TelemetryBrowser. Its capabilities include stealing credentials from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote-shell execution, system fingerprinting and encrypted command-and-control communications.
Commands concealed in HTML
A notable feature of ASHVEIN is its use of invisible HTML elements to hide tasking. TrendAI said some variants also use a GitHub-based dead-drop resolver as a fallback mechanism. This gives operators multiple ways to provide instructions to an infected endpoint beyond a single fixed command-and-control path.
UAC-0099 has deployed ASHVEIN through DLL sideloading, also known as FORGECLAMP, VHD containers and purpose-built .NET droppers. One executable, AnswerFromPolice, embeds a Microsoft Word document presented as a response from the National Police of Ukraine. It displays that decoy to the recipient while deploying the malware in the background.
TrendAI said the combination of an institutional impersonation and a credible document is intended to increase the chance that a recipient opens and trusts the file. The delivery chain therefore pairs social engineering with execution techniques designed to conceal the payload.
Evolution of the UAC-0099 toolkit
CERT-UA first documented UAC-0099 in June 2023, although the group has targeted Ukrainian government, defence, border guard and logistics entities since at least mid-2022. Its activity emerged after Russia’s full-scale invasion of Ukraine. ESET said in its November 2025 APT Activity Report that the group can act as an initial access broker for Sandworm.
The actor has expanded its toolset over time, moving from PowerShell- and Go-based tools to compiled C# binaries and .NET Reactor-protected binaries concealed in steganographic image files. Earlier families include LONEPAGE, THUMBCHOP, CLOGFLAG, SEAGLOW and OVERJAM; later activity included MATCHBOIL, MATCHWOK, DRAGSTARE, BadPaw, MeowMeow, LUNCHPOKE, BURNYBEAR and MATCHBOIL.V2.
TrendAI identified five ASHVEIN builds compiled between October 8 and October 23, 2025, using three distinct packing variants. ASHVEIN overlaps with DRAGSTARE in credential theft, screenshots, file collection and WMI fingerprinting, but differs in its packing approach and build environment. TrendAI assessed that the overlap and separate developer accounts point to parallel tool development for the same operational requirement.
Downloader and analysis evasion changes
MATCHBOIL, a C# downloader under active development since at least April 2024, is responsible for downloading, installing and persisting another payload. ESET observed newer iterations as DLL files executed by a custom C# loader. The malware checks for a virtual environment and stops if the operating-system installation date is 10 or more days older than the date the artifact runs.
ESET also observed GuardBreaker used against a Ukrainian target. A malicious VBScript carrying MATCHBOIL embeds a prompt requesting instructions for making a nuclear weapon, apparently seeking to trigger large language model safety mechanisms before automated analysis can assess the rest of the code.
TrendAI said the targeting appears to have expanded beyond government and military organisations to civilian logistics and infrastructure operators. For organisations in the affected sectors, the practical implication is to validate document-origin claims, monitor DLL sideloading and VHD-based execution, and investigate unusual outbound activity involving GitHub-based resolvers and encrypted command channels.

