The cybersecurity threat group known as UAC-0099 has been linked to a newly identified .NET-based malware called ASHVEIN. This remote access trojan (RAT) has been actively used in attacks against Ukrainian government officials. TrendAI, a cybersecurity firm, has labeled this cluster as Earth Sirrush, previously known as SHADOW-EARTH-065.
ASHVEIN’s Capabilities and Deployment
ASHVEIN, internally called ‘TelemetryBrowser,’ integrates several malicious functionalities, including credential theft from popular browsers like Chrome and Firefox, the ability to capture screenshots using GDI, and remote control through PowerShell. Additionally, it utilizes encrypted command-and-control (C2) communications, making it a versatile tool for cyber espionage.
TrendAI reports that ASHVEIN conceals its operations within invisible HTML elements. Different versions of the malware have employed a GitHub-based resolver as a secondary tactic, while its distribution methods encompass DLL sideloading, VHD containers, and specialized .NET droppers.
Historical Context and Evolution
First documented by CERT-UA in June 2023, UAC-0099 has a history of targeting Ukrainian governmental and military sectors, particularly since mid-2022. The group’s activities have intensified following Russia’s extensive military actions in Ukraine.
According to ESET, a cybersecurity provider, UAC-0099 may function as an initial access facilitator for the Russian APT group Sandworm. Over time, the group has diversified its malware portfolio, transitioning from PowerShell- and Go-based tools to more secure C# and .NET binaries, often hidden within image files.
Recent Developments and Tactical Shifts
Recent malware families linked to UAC-0099 include LONEPAGE, THUMBCHOP, and most recently, ASHVEIN. Between October 8 and October 23, 2025, five ASHVEIN builds were compiled using three different packing techniques. Despite functional similarities with DRAGSTARE, such as credential theft and file collection, significant differences in their development environments suggest parallel tool creation.
UAC-0099 employs varied delivery methods for ASHVEIN, including the use of decoy documents like AnswerFromPolice, which masquerades as official communication from the Ukrainian National Police. This tactic aims to increase the likelihood of the malware being executed by unsuspecting users.
Implications and Future Outlook
The ongoing activities of UAC-0099 highlight a sophisticated and evolving threat landscape. Their ability to adapt and enhance their malware arsenal poses a significant challenge to cybersecurity defenses. With the conflict in Ukraine continuing, understanding and disrupting these cyber operations remains crucial.
As the threat actor extends its focus beyond military targets to civilian infrastructure, the need for robust cybersecurity measures grows. The evolving tactics, such as the recent employment of GuardBreaker to bypass AI-based analysis, underline the importance of continuous vigilance and advanced threat detection capabilities.
