Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

UAC-0099's ASHVEIN RAT: A Sophisticated Malware Threat to Ukrainian Government Personnel




UAC-0099's ASHVEIN RAT: A Sophisticated Malware Threat to Ukrainian Government Personnel

A new threat actor, UAC-0099, linked to the Russia-aligned threat actor, has been identified using a previously unknown .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. ASHVEIN has been found to be used in attacks targeting Ukrainian government personnel, and its functionality includes credential theft, surveillance, and remote-control capabilities. The use of AI-powered techniques by UAC-0099 to accelerate reconnaissance, compromise identities and escalate access is a concerning development, and the targeting of civilian logistics and infrastructure operators that keep Ukraine supplied by UAC-0099 is also a notable expansion of the threat actor's activities. This article provides an in-depth analysis of the ASHVEIN RAT and its implications for organizations and individuals.

  • Ukraine-based firm TrendAI has documented a previously unknown .NET infostealer and RAT called ASHVEIN linked to Russia-aligned threat actor UAC-0099.
  • ASHVEIN is used in attacks targeting Ukrainian government personnel, with functionalities including credential theft, surveillance, and remote-control capabilities.
  • UAC-0099 has a history of targeting Ukrainian government, defense, and logistics entities since mid-2022.
  • The threat actor has expanded its malware arsenal over the years, shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries.
  • UAC-0099 has employed various malware families, including LONEPAGE, THUMBCHOP, CLOGFLAG, SEAGLOW, and MATCHBOIL, among others.
  • The use of steganographic image files to conceal malware binaries has become a hallmark of UAC-0099's tradecraft.
  • ASHVEIN brings together credential theft, surveillance, and remote-control capabilities, making it a sophisticated tool in UAC-0099's arsenal.
  • The threat actor uses AI-powered techniques to accelerate reconnaissance, compromise identities, and escalate access.
  • The discovery of ASHVEIN highlights the need for organizations to remain vigilant against the latest threats from Russia-aligned threat actors.



  • Ukraine-based cybersecurity firm TrendAI has recently documented a previously unknown .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN, which is linked to the Russia-aligned threat actor known as UAC-0099. The malware has been found to be used in attacks targeting Ukrainian government personnel, and its functionality includes credential theft, surveillance, and remote-control capabilities.

    ASHVEIN is a sophisticated malware that brings together various capabilities, including credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control (C2) communications. The malware is designed to be stealthy, with some variants hiding tasking inside invisible HTML elements. TrendAI has also observed the use of a technique called GuardBreaker against a Ukrainian target to undermine artificial intelligence (AI)-assisted analysis.

    The threat actor behind ASHVEIN, UAC-0099, has a history of targeting Ukrainian government, defense, border guard, and logistics entities since at least mid-2022. ESET's research indicates that the cyber espionage crew can serve as an initial access broker for Sandworm, a Russian advanced persistent threat (APT) group best known for its destructive attacks against Ukraine. UAC-0099 has steadily expanded its malware arsenal over the years, shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files.

    The malware family deployed by UAC-0099 over the years includes LONEPAGE, THUMBCHOP, CLOGFLAG, SEAGLOW, and OVERJAM, which were used between 2022 and 2024. More recently, the threat actor has employed MATCHBOIL, MATCHWOK, DRAGSTARE, and BadPaw, among other malware families, between February and April 2026. The use of steganographic image files to conceal malware binaries has become a hallmark of UAC-0099's tradecraft.

    ASHVEIN, also known as TelemetryBrowser, brings together credential theft, surveillance, and remote-control capabilities, making it a sophisticated tool in the threat actor's arsenal. The malware uses multiple delivery methods for ASHVEIN, including DLL sideloading, VHD containers, and purpose-built .NET droppers. One such .NET executable is AnswerFromPolice, which embeds a Microsoft Word document that purports to be a response from the National Police of Ukraine while deploying the malware in the background.

    The combination of institutional impersonation and credible decoy content used by UAC-0099 to increase the likelihood that recipients will open and trust the file is a notable tactic in the malware's delivery method. The use of AI to accelerate reconnaissance, compromise identities and escalate access by UAC-0099 is also noteworthy, as attackers are using AI to accelerate reconnaissance, compromise identities and escalate access.

    TrendAI's research into UAC-0099 has provided valuable insights into the threat actor's tactics, techniques, and procedures (TTPs). The fact that UAC-0099 has steadily expanded its malware arsenal over the years, shifting from PowerShell- and Go-based tools to compiled C# and .NET Reactor-protected binaries concealed within steganographic image files, is a testament to the threat actor's creativity and adaptability.

    The use of AI-powered techniques by UAC-0099 to undermine AI-assisted analysis and deploy malicious Visual Basic Script (VBScript) to embed a prompt asking for instructions to make a nuclear weapon in an attempt to deliberately trigger a large language model's (LLM) safety mechanisms is a concerning development. The targeting of civilian logistics and infrastructure operators that keep Ukraine supplied by UAC-0099 is also a notable expansion of the threat actor's activities.

    Overall, the discovery of ASHVEIN, a sophisticated malware threat linked to UAC-0099, highlights the need for organizations to remain vigilant against the latest threats from Russia-aligned threat actors. The use of AI-powered techniques by UAC-0099 to accelerate reconnaissance, compromise identities and escalate access underscores the importance of effective cybersecurity measures to prevent such threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/UAC-0099s-ASHVEIN-RAT-A-Sophisticated-Malware-Threat-to-Ukrainian-Government-Personnel-ehn.shtml

  • https://thehackernews.com/2026/10/uac-0099-targets-ukrainian-government.html


  • Published: Thu Oct 8 11:40:19 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us