UAC- 0099, a Russia-aligned threat actor, has been linked to a .NET infostealer and remote access trojan named ASHVEIN (internal name TelemetryBrowser). TrendAI attributes current activity to Ukrainian government personnel, part of the Earth Sirrush cluster. The operators have evolved their toolkit over several years, shifting from PowerShell and Go to compiled C#/.NET-based binaries that increasingly hide in steganographic images and utilise various delivery methods.
ASHVEIN combines credential theft (notably from Chrome and Firefox), screen capture, file enumeration and retrieval, and PowerShell-based remote shell capabilities, with encrypted C2 communications. Some variants conceal tasking inside invisible HTML elements, and the threat group has used GitHub-based dead drops as fallback resolvers.
Delivery methods include DLL sideloading (FORGECLAMP), VHD containers, and bespoke .NET droppers; one example is AnswerFromPolice, a decoy Word document impersonating the National Police of Ukraine used to deploy the malware. The actor’s evolving playbook also includes downloader tools such as MATCHBOIL (and its variants), which are built to download and persist payloads, with anti-VM checks and environment awareness.
Evidence and context from CERT-UA (June 2023) show a long-running emphasis on Ukrainian government, defence, border guards, and logistics sectors, with recent indicators suggesting civilian infrastructure targets as the conflict drags on. ESET notes the potential for ASHVEIN to act as an initial access broker for Sandworm.
Practical responses imply heightened monitoring of HTML-embedded tasking, DLL sideloading, and .NET dropper chains, alongside cross-sector vigilance for novel decoy lures and steganographic delivery.