Full Report
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
Analysis Summary
# Threat Actor: UAC-0099
## Attribution & Identity
* **Actor Identification:** UAC-0099 is a Russia-aligned threat actor first documented by CERT-UA in June 2023.
* **Aliases:** Earth Sirrush (Trend Micro/TrendAI), SHADOW-EARTH-065.
* **Known Associations:** Linked as a potential initial access broker for **Sandworm** (a Russian APT group). There are also overlaps in TTPs or campaigns involving **APT28**.
## Activity Summary
UAC-0099 has been active since at least mid-2022, following Russia's full-scale invasion of Ukraine. Recent operations (2025–2026) involve the deployment of a new .NET-based remote access trojan (RAT) and infostealer named **ASHVEIN** (internally called "TelemetryBrowser"). The actor has transitioned from PowerShell and Go-based tools to sophisticated, obfuscated .NET binaries and steganography.
## Tactics, Techniques & Procedures
* **Defense Evasion:** Use of .NET Reactor protection, steganographic image files, and hiding commands within invisible HTML elements.
* **Persistence & Execution:** DLL sideloading (internally called FORGECLAMP), use of VHD containers, and dedicated .NET droppers (e.g., "AnswerFromPolice").
* **C2 Communication:** Encrypted C2 communications; use of GitHub-based dead drop resolvers as a fallback mechanism.
* **Credential Theft:** Targeted extraction from Google Chrome and Mozilla Firefox.
* **Surveillance:** GDI-based screenshot capture and WMI-based system fingerprinting.
* **MITRE ATT&CK Techniques (Inferred from text):**
* T1574.002 (DLL Side-Loading)
* T1059.001 (PowerShell)
* T1027.003 (Steganography)
* T1555.003 (Credentials from Web Browsers)
* T1102.001 (Dead Drop Resolver)
## Targeting
* **Sectors:** Government, Defense, Border Guard, and Logistics.
* **Geography:** Ukraine.
* **Victims:** Specifically Ukrainian government personnel.
## Tools & Infrastructure
* **Malware Families:**
* **ASHVEIN (TelemetryBrowser):** .NET RAT/Infostealer (Current).
* **Loaders/Backdoors:** LONEPAGE, MATCHBOIL, MATCHWOK, BURNYBEAR, BadPaw (CINDERBLOT).
* **Stealers:** THUMBCHOP, DRAGSTARE (NordDragonScan).
* **Interactive/Proxy:** SEAGLOW, OVERJAM, MeowMeow.
* **Specialized:** LUNCHPOKE (Masquerades as Notepad++ plugin), CLOGFLAG (Keylogger).
* **Infrastructure:**
* GitHub (Dead drop resolver)
* VHD (Virtual Hard Disk) containers for delivery.
## Implications
UAC-0099 represents a persistent and evolving threat focused on Ukrainian state infrastructure. Their role as an initial access broker for Sandworm indicates they are a critical component of Russia’s broader cyber-espionage and sabotage ecosystem. The shift toward parallel development of modular .NET tools (ASHVEIN and DRAGSTARE) suggests a well-resourced operation with distinct development tracks for different mission requirements.
## Mitigations
* **Application Control:** Monitor for unauthorized DLL loadings and restrict the use of side-loading vulnerable applications.
* **File Analysis:** Implement deep inspection of VHD files and .NET binaries, specifically looking for .NET Reactor packing signatures.
* **Network Monitoring:** Watch for unusual traffic to GitHub (dead drop resolvers) and monitor for encrypted C2 patterns hidden in HTML elements.
* **Email Security:** Heightened scrutiny of attachments mimicking official documents (e.g., "AnswerFromPolice").