Skip to main content
Emerging ThreatsMalware & Ransomware

UAC-0099 Deploys ASHVEIN RAT in Targeted Attacks on Ukrainian Government Personnel

Ukrainian government office with computer workstation on desk near window.

"ASHVEIN also hides tasking inside invisible HTML elements," TrendAI said.

ASHVEIN (also called TelemetryBrowser): capabilities and unique tradecraft

TrendAI has attributed a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN to the Russia‑aligned threat actor UAC‑0099. The developers internally refer to the malware as "TelemetryBrowser." According to TrendAI, ASHVEIN blends credential theft, surveillance and remote‑control features: credential harvesting from Chrome and Firefox; GDI‑based screenshot capture; file enumeration and retrieval; PowerShell remote shell execution; system fingerprinting via WMI; and encrypted command‑and‑control communications.

Among the behaviors that set ASHVEIN apart is its ability to hide tasking inside invisible HTML elements, a form of covert command embedding that TrendAI highlighted explicitly. Some ASHVEIN variants also use a GitHub‑based dead drop resolver as a fallback mechanism, increasing the flexibility of its command retrieval options.

UAC‑0099's delivery methods: DLL sideloading, VHDs and social impersonation

TrendAI observed multiple delivery mechanisms for ASHVEIN, including DLL sideloading (tracked as FORGECLAMP), virtual hard disk (VHD) containers, and purpose‑built .NET droppers. One named .NET executable, AnswerFromPolice, embeds a Microsoft Word document that impersonates the National Police of Ukraine. AnswerFromPolice displays the decoy document while deploying the malware in the background — "a combination of institutional impersonation and credible decoy content" designed, TrendAI said, to increase the chance a recipient will open and trust the file.

Other artifacts in UAC‑0099's toolset mimic legitimate software: TrendAI reported LUNCHPOKE, a .NET DLL that masquerades as a Notepad++ plugin, among recent items observed between April and July 2026.

Toolchain evolution: from PowerShell and Go to compiled C# and steganography

UAC‑0099’s malware portfolio has evolved steadily since mid‑2022. The group was first documented by the Computer Emergency Response Team of Ukraine (CERT‑UA) in June 2023 and has a history of targeting Ukrainian government, defense, border guard and logistics entities since at least mid‑2022. ESET, in its APT Activity Report published in November 2025, noted UAC‑0099 can serve as an initial access broker for Sandworm.

Across 2022–2026, TrendAI and ESET trace a shift from PowerShell‑ and Go‑based tools toward compiled C# and .NET Reactor‑protected binaries, some concealed within steganographic image files. The record lists many named families and dates: LONEPAGE, THUMBCHOP, CLOGFLAG, SEAGLOW and OVERJAM (2022–2024); MATCHBOIL, MATCHWOK and DRAGSTARE/NordDragonScan (2024–2025); ASHVEIN (October 2025); BadPaw/CINDERBLOT and MeowMeow (February–April 2026); and LUNCHPOKE, BURNYBEAR and MATCHBOIL.V2 (April–July 2026).

TrendAI reported five ASHVEIN builds compiled between October 8 and October 23, 2025, across three packing variants. Functional overlap with the earlier DRAGSTARE family — credential theft, screenshots, file collection and WMI fingerprinting — exists, but TrendAI noted separate build environments and packing approaches consistent with parallel development under different developer accounts.

GuardBreaker: deliberate interference with AI analysis

TrendAI also documented an operational innovation aimed at undermining AI‑assisted analysis. Against a Ukrainian target, UAC‑0099 deployed a malicious Visual Basic Script that embeds a prompt asking for instructions to make a nuclear weapon. TrendAI describes this as an attempt to deliberately trigger a large language model's safety mechanisms and prevent the model from analyzing the remainder of the code. That VBScript functioned as a conduit for MATCHBOIL, the group's long‑running C# downloader.

MATCHBOIL itself has been under active development since at least April 2024, ESET researchers report. The downloader's recent iterations include a DLL executed by a custom C# loader and anti‑analysis checks such as aborting execution when the OS installation date is older than ten days relative to the artifact execution date, demonstrating an intent to evade both virtualized analysis and time‑based detection heuristics.

What this means for Ukrainian government personnel, civilian logistics operators, and security teams

  • Ukrainian government personnel: CERT‑UA documented UAC‑0099 in June 2023, and TrendAI reports continued targeting. The combination of institutional impersonation (AnswerFromPolice) and credible decoys raises immediate operational risk for email and document workflows.
  • Civilian logistics and infrastructure operators: TrendAI states targeting has expanded beyond government and military organizations to include civilian logistics and infrastructure operators that keep Ukraine supplied, increasing the stakes for organizations involved in supply chains and transport.
  • Security teams and incident responders: The observed shift to compiled C#, .NET Reactor protection, steganographic carriers, invisible HTML tasking, GitHub fallback resolvers, and GuardBreaker prompts changes the detection surface. ESET’s reporting on MATCHBOIL shows the downloader is being hardened with anti‑VM and timing checks, meaning defenders must tune detection for both loader behavior and misuse of legitimate platforms like GitHub.

The record assembled by TrendAI and ESET portrays a threat actor iterating deliberately: new loaders, new packing, and new evasion techniques deployed alongside social and technical delivery tricks. Whether defenders, analysts and the organizations under attack can outpace innovations such as invisible HTML commands, GitHub dead drops and GuardBreaker‑style prompts will shape how effectively Ukraine’s networks — and the civilian systems that sustain them — can be protected.

Original report