UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
Russia-aligned UAC-0099 deployed the ASHVEIN RAT against Ukrainian government staff, hiding tasking in HTML.
TrendAI attributes a new .NET infostealer and RAT, ASHVEIN (internally TelemetryBrowser), to Russia-aligned UAC-0099, also tracked as Earth Sirrush, in attacks on Ukrainian government personnel. ASHVEIN steals Chrome and Firefox credentials, captures screenshots, collects files, runs PowerShell, and hides tasking in invisible HTML, with a GitHub dead-drop fallback. Delivery includes DLL sideloading, VHD containers, and a National Police of Ukraine decoy. ESET also reported a VBScript that embeds a prohibited-weapons prompt to trip LLM safety filters and hinder analysis of the MATCHBOIL loader.