UAC-0099’s New RAT “ASHVEIN” Spies on Ukraine via Hidden HTML Commands

A cyberespionage group aligned with Russia, known as UAC-0099, has rolled out a newly discovered tool dubbed ASHVEIN (also internally called TelemetryBrowser) to infiltrate Ukrainian government resources. Researchers uncovered that this.NET-based remote access trojan (RAT) merges credential theft, surveillance, and remote control under one umbrella. It builds on UAC-0099’s previous toolset expansion while introducing stealthier methods of command delivery.

What ASHVEIN Can Do

ASHVEIN has been equipped to harvest credentials from both Chrome and Firefox browsers, take screenshots via GDI calls, scan and retrieve files, execute PowerShell shells remotely, and perform system fingerprinting. Communications with its command-and-control (C2) servers are encrypted. Crucially, the trojan hides its directives inside invisible HTML elements, complicating detection. As fallback options, some variants use a GitHub-based dead-drop resolver.

Delivery and Evolution

UAC-0099 has adopted multiple infection channels for ASHVEIN including DLL sideloading (a technique named FORGECLAMP), virtual hard-disk containers, and bespoke.NET droppers. One attack variant names “AnswerFromPolice” uses a malicious.NET executable that shows a fake Microsoft Word response from Ukraine’s National Police while detonating the malware behind the scenes.

This release is part of a steady shift in the group’s malware toolkit. From 2022 through 2024, UAC-0099 was focused on lighter tools like PowerShell loaders, Go-based backdoors, keyloggers, browser stealers, and reverse proxy tools. In late 2025 the group added ASHVEIN to its arsenal, followed by a stream of.NET-based loaders, backdoors, and augmented downloaders throughout 2026. The MATCHBOIL family, for example, has grown to include DLLs executed by custom loaders that screen for virtual environments and check system metadata before running.

Wider Targeting & New Tradecraft

Although governmental and defense bodies remain primary targets, UAC-0099’s activities have expanded into border guard agencies, logistics operations, and civilian infrastructure operators—particularly those with roles in sustaining Ukraine’s supply lines.

A novel trick in the group’s playbook: using a malicious VBScript to try to distract AI-based analysis tools. One version embeds a prompt asking the system to show instructions for making a nuclear weapon—an attempt to trigger a model’s safety protocols and block scrutiny of the rest of the malicious code. This tactic was found in conjunction with MATCHBOIL tools.

UAC-0099 has been on CERT-UA’s radar since at least mid-2022, targeting state, defense, and logistics officials. In November 2025, researchers linked it as an initial access broker for the notorious Sandworm APT group.

Why this matters:ASHVEIN reflects a clear evolution in cyberespionage targeting Ukraine—fusing multiple spying tools into one sophisticated RAT, hiding instructions in HTML, and developing delivery mechanisms that mimic trusted sources. Against the backdrop of ongoing conflict, monitoring Ukraine’s defense, infrastructure, and government makes high-stakes cybersecurity a frontline issue.