Back to Newsroom
Threat Intel

UAC-0099 Unleashes ASHVEIN: A New .NET RAT Hiding Commands in Invisible HTML

A previously undocumented .NET infostealer and remote access trojan, attributed to the Russia-aligned UAC-0099 group, conceals its command tasking inside invisible HTML elements as the threat actor's campaign against Ukraine expands into civilian supply chains.

UAC-0099 Unleashes ASHVEIN: A New .NET RAT Hiding Commands in Invisible HTML

UAC-0099 Unleashes ASHVEIN: A New .NET RAT Hiding Commands in Invisible HTML

Security researchers have attributed a previously undocumented malware strain, internally called "TelemetryBrowser" by its developers and tracked publicly as ASHVEIN, to the Russia-aligned threat actor UAC-0099. The wider espionage cluster is being followed in the industry under the name Earth Sirsurh.

What happened

ASHVEIN is a .NET-based infostealer and remote access trojan built for credential theft, surveillance, and remote control. It lifts saved credentials from Chrome, Edge, and Firefox, captures screenshots, enumerates and retrieves files, opens a PowerShell-based remote shell, fingerprints the host system, and communicates with its command-and-control infrastructure over encrypted channels.

Its most distinctive trait is how it receives instructions: ASHVEIN hides its tasking inside invisible HTML elements, a technique designed to blend command traffic into what looks like ordinary web content. Some variants fall back on a GitHub-hosted dead-drop resolver if primary channels fail. Delivery relies on DLL sideloading, VHD container files, and purpose-built .NET droppers — including one sample bundled with a decoy Microsoft Word document impersonating Ukraine's National Police to convince targets to open it.

Researchers tied five separate ASHVEIN builds, split across three distinct packing methods, to a two-week compilation window in October. Functionally, ASHVEIN overlaps heavily with another UAC-0099 tool, DRAGSTARE — both steal credentials, screenshots, and files, and both fingerprint systems over WMI — but the two were compiled under different developer accounts and build environments, pointing to parallel tool development inside the same operation rather than a straight evolution of one codebase.

ASHVEIN is only the latest entry in a fast-growing toolkit. Since 2022, UAC-0099 has fielded well over a dozen distinct malware families — loaders, keyloggers, backdoors, downloaders, and stealers — with its C#-based MATCHBOIL downloader under continuous refinement since mid-2024. The newest MATCHBOIL builds run as a DLL launched by a custom loader and will refuse to execute inside a virtual machine or on a system whose install date is more than ten days older than the sample itself, an anti-sandbox check meant to frustrate automated analysis.

Perhaps the most striking recent development: researchers observed UAC-0099 testing a technique against a Ukrainian target that goes after AI-assisted defenses directly. A malicious VBScript embedded a written prompt asking an AI system for instructions to build a nuclear weapon — an attempt to trip the safety guardrails of an AI model tasked with analyzing the script, so that it would refuse to inspect the malicious code that followed.

Why it matters

UAC-0099 has targeted Ukrainian government, defense, border-guard, and legal entities since mid-2022, and has reportedly acted as an initial access broker for Sandworm, the destructive Russian military-linked APT group. Its targeting has now broadened beyond government and military institutions to civilian logistics and infrastructure operators that keep supply lines into Ukraine running — organizations that often have fewer security resources than hardened government networks, but whose disruption carries real operational consequences.

The prompt-injection attempt against AI-assisted analysis is also a signal worth watching well beyond Ukraine: as security teams increasingly lean on AI models to triage and analyze suspicious code, adversaries are already probing how to manipulate those models into standing down.

What to do

  • Treat unsolicited Word documents referencing government or law-enforcement bodies as high-risk, especially where the sender or delivery channel can't be verified.
  • Monitor for DLL sideloading and unexpected VHD mounts on endpoints, particularly where the loaded DLL executes from an unusual path.
  • Flag outbound HTTP traffic that embeds data in invisible or hidden HTML elements rather than conventional parameters — a low-noise but detectable C2 pattern.
  • If your defenses include AI-assisted triage, test and harden those tools against prompt-injection content embedded inside scripts and documents, not just inside user-facing text fields.
  • Organizations in logistics, transport, or infrastructure supply chains supporting Ukraine should assume they are now plausible targets, not just bystanders, and align monitoring accordingly.
SHARE