Skip to content
UAC-0099 Targets Ukrainian Government with ASHVEIN Malware

UAC-0099 Targets Ukrainian Government with ASHVEIN Malware

First seen 8 Oct 2026, 17:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 18:37 UTC
  • •UAC-0099 is targeting Ukrainian government personnel with the ASHVEIN malware.
  • •ASHVEIN combines credential theft, surveillance, and remote access capabilities.
  • •The threat actor has evolved its malware arsenal since mid-2022, utilizing various delivery methods.

The Russia-aligned threat actor UAC-0099 has been linked to a new .NET infostealer and RAT named ASHVEIN, targeting Ukrainian government personnel. This malware, also referred to as 'TelemetryBrowser,' features capabilities such as credential theft from Chrome and Firefox, screenshot capture, and remote shell execution. ASHVEIN is part of a broader malware arsenal developed by UAC-0099, which has been active since at least mid-2022, following Russia's full-scale invasion of Ukraine. The group has utilized various delivery methods, including DLL sideloading and VHD containers, and has been involved in spear-phishing campaigns against government and defense entities. TrendAI reports that ASHVEIN overlaps functionally with previous malware like DRAGSTARE but has distinct differences. The threat actor has evolved its tools over the years, transitioning from PowerShell and Go-based malware to .NET-based binaries. The ongoing cyber espionage efforts by UAC-0099 highlight the persistent threat to Ukrainian infrastructure amidst geopolitical tensions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-06-01
UAC-0099 first documented
The Computer Emergency Response Team of Ukraine (CERT-UA) documented UAC-0099's activities targeting Ukrainian entities.
The Hacker News
2025-10-08
ASHVEIN malware identified
TrendAI reported the identification of ASHVEIN, a new .NET infostealer and RAT used by UAC-0099.
TrendAI
2026-10-08
ASHVEIN capabilities detailed
TrendAI detailed ASHVEIN's capabilities, including credential theft and remote control features.
The Hacker News

More articles in this cluster (2)

Following this threat?

Track Earth Sirrush, Ashvein and CVE-2023-38831 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is ASHVEIN?
ASHVEIN is a newly identified .NET infostealer and RAT used by the threat actor UAC-0099.
Who is targeted by UAC-0099?
UAC-0099 primarily targets Ukrainian government personnel and defense entities.
What are the capabilities of ASHVEIN?
ASHVEIN features credential theft, screenshot capture, file retrieval, and remote command execution.