Threat reportAPTTL-2026-3083
UAC-0099 (Earth Sirrush) Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
UAC-0099 (Earth Sirrush) Targets Ukrainian Government (TL-2026-3083), also tracked as TelemetryBrowser, is a high-severity advanced persistent threat campaign, first published 2026-10-09 and last reviewed 2026-10-10. It is attributed to UAC-0099 (Russia) with medium confidence, affects Microsoft Windows, maps to 33 MITRE ATT&CK techniques (T1005, T1027.003, T1027.009), and is covered by 9 detection rules and 38 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 33MITRE ATT&CK
- Actors
- 2UAC-0099
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 38Indicators of compromise
Key facts for TL-2026-3083
- Threat ID
- TL-2026-3083
- Also known as
- TelemetryBrowser, ASHVEIN, MATCHBOIL, GuardBreaker
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- UAC-0099, Earth Sirrush
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, police - law enforcement, transport, manufacturing, energy, tax-authority, logistics
- Target regions
- ukraine
- Detection rules
- 9
- Indicators of compromise
- 38
- Updates
- 2026-10-10 · revalidated 1× · latest source
Malware and tooling in UAC-0099 (Earth Sirrush) Targets Ukrainian Government
Malware and tooling: ASHVEIN, BadPaw, DRAGSTARE, FORGECLAMP, MATCHBOIL
How UAC-0099 (Earth Sirrush) Targets Ukrainian Government works
Russia-aligned UAC-0099 (tracked by TrendAI as Earth Sirrush, formerly SHADOW-EARTH-065) is targeting Ukrainian government personnel with the .NET infostealer/RAT ASHVEIN (developer name TelemetryBrowser), which hides tasking in invisible HTML elements and can use a GitHub-based dead drop resolver as fallback C2. ESET reported that UAC-0099 acted as an initial access broker for Sandworm.
UAC-0099 is a Russia-aligned intrusion set that CERT-UA first documented in June 2023, with targeting of Ukraine observed since mid-2022. TrendAI tracks the cluster as Earth Sirrush (previously SHADOW-EARTH-065) and describes four years of evolving espionage tooling. Victimology centres on Ukrainian government ministries, the defense forces, the State Border Guard Service, the National Police, tax authorities, the Ministry of Justice, transport/logistics operators and defense supply chain entities. ESET telemetry for the MATCHBOIL loader shows Ukraine-only victims in transportation (Jul-Aug 2025), manufacturing (Dec 2025) and energy (Jun 2026).
ASHVEIN is a .NET infostealer and RAT whose developer-assigned name is TelemetryBrowser ("TelemetryUP" branding appears in its metadata). Capabilities include Chrome credential extraction (via DPAPI) and Firefox profile data theft, GDI-based screenshot capture, file enumeration and retrieval, a PowerShell remote shell, WMI-based system fingerprinting and encrypted C2. Per TrendAI, ASHVEIN hides tasking inside invisible HTML elements, and some variants use a GitHub-based dead drop resolver as fallback C2. It checks for analysis tools (Wireshark, IDA, OllyDbg, Fiddler, Process Monitor) and uses XOR-based string encryption shared with MATCHBOIL and DRAGSTARE, as well as anti-debugging and TLS certificate-validation bypass. Five ASHVEIN builds were compiled between 2025-10-08 and 2025-10-23 across three packing variants. It overlaps functionally with the group's DRAGSTARE stealer but uses different packing and separate build environments.
Delivery uses spearphishing, DLL sideloading (FORGECLAMP), VHD containers and dedicated .NET droppers; the AnswerFromPolice dropper embeds a Word decoy impersonating a National Police of Ukraine response. The wider toolset includes the loaders LONEPAGE, SEAGLOW and OVERJAM, the .NET loaders MATCHBOIL (with MATCHBOIL.V2) and MATCHWOK, CINDERBLOT/BadPaw (PNG steganography, March 2026), and a July 2026 chain of the LUNCHPOKE malicious Notepad++ plugin, BURNYBEAR and MATCHBOIL.V2. MATCHBOIL is delivered by spearphishing links to an archive containing a VBScript that downloads and runs the loader. It persists via HKCU Run keys or scheduled tasks and uses a three-request HTTPS C2 exchange with a hex-encoded payload returned in HTML. Newer variants use sandbox checks (Windows Event ID 6013 uptime, OS-install-date age of 10 days or more) and Eziriz .NET Reactor obfuscation.
In September 2026 a malicious VBScript conduit for MATCHBOIL embedded prompts about nuclear weapons ("GuardBreaker") intended to trigger LLM safety mechanisms and disrupt AI-based analysis; it was reportedly discontinued. ESET's APT Activity Report (Q2-Q3 2025, published November 2025) confirmed UAC-0099 performed initial access and handed validated targets to Sandworm. Infrastructure is fronted by Cloudflare, uses Regery.com as registrar and BL Networks (AS399629) backend IPs on BitLaunch VPSes. Severity is analyst-assigned; no CVE is tied to the ASHVEIN chain (CVE-2023-38831 WinRAR exploitation was a 2023 tactic of the group).
MITRE ATT&CK techniques used in TL-2026-3083
Collection
T1005 Data from Local System; T1113 Screen Capture
Defense Evasion
T1027.003 Obfuscated Files or Information; T1027.009 Obfuscated Files or Information; T1036.003 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.005 System Binary Proxy Execution; T1497.001 System Checks; T1574.001 DLL; T1622 Debugger Evasion
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.005 Visual Basic; T1203 Exploitation for Client Execution; T1204.002 Malicious File
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder; T1574.002 Hijack Execution Flow
Command and Control
T1071.001 Web Protocols; T1090.004 Proxy; T1102.001 Dead Drop Resolver; T1105 Ingress Tool Transfer; T1573.002 Asymmetric Cryptography
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1518.001 Software Discovery
Credential Access
T1555.003 Credentials from Web Browsers
Initial Access
T1566.001 Phishing; T1566.002 Spearphishing Link
Resource Development
T1583.001 Domains; T1583.003 Virtual Private Server; T1587.001 Malware
Affected products and versions in UAC-0099 (Earth Sirrush) Targets Ukrainian Government
- Microsoft — Windows
Vulnerable versions: Windows endpoints used by Ukrainian government and defense-sector personnel
Remediation for UAC-0099 (Earth Sirrush) Targets Ukrainian Government
Immediate actions
- Block the listed domains and BL Networks IPs at DNS/proxy/firewall and hunt for historical connections
- Hunt for Global\PlannerAssistant mutex, %LOCALAPPDATA%\DeviceMonitor, MeowCheck and SMTPClient directories, and scheduled tasks UpdateCheckers\DailyPlanner, MailClient\Checker and Updates\CheckTask
- Alert on VBScript or archive execution from mail-linked downloads and on mounting of VHD files from user-writable paths
- Alert on new files in C:\Users\Public\Libraries\ and on renamed copies of schtasks.exe
- Reset credentials stored in Chrome and Firefox on any suspected host
Workarounds
- Restrict outbound access to github.com raw content from non-developer hosts where feasible
- Disable Windows Script Host for users without a business need
Longer-term hardening
- Block or restrict VHD mounting and script host execution (wscript/cscript) for standard users
- Deploy EDR with .NET behavioral and WMI-query detection
- Do not rely solely on LLM-based analysis of scripts; sanitize or segregate untrusted script content from AI triage prompts
- Train Ukrainian government and defense-sector staff on police/border-guard/tax-authority themed lures
Timeline of UAC-0099 (Earth Sirrush) Targets Ukrainian Government
- UAC-0099 targeting of Ukraine begins (mid-2022 per CERT-UA; month approximate)
- Earth Sirrush used WinRAR CVE-2023-38831 via the OVERJAM Go loader in 2023 (month approximate).
- CERT-UA initially documents UAC-0099 (June 2023; day approximate)
- Earliest MATCHBOIL compilation timestamps (April 2024; day approximate)
- MATCHBOIL first publicly documented by CERT-UA after July-August 2025 ESET telemetry detections against Ukrainian transportation companies (day approximate)
- Five ASHVEIN builds compiled between 2025-10-08 and 2025-10-23 across three packing variants
- ESET APT Activity Report (Q2-Q3 2025) identifies UAC-0099 as initial access broker handing targets to Sandworm (month approximate)
- C2 domain virtualdailyplanner.pro first seen
- C2 domain flycloud-service.com (64.95.10.223) first seen; CINDERBLOT/BadPaw PNG steganography campaign observed in March 2026
- MATCHBOIL.V2 DLL variant with OS-install-date virtual environment check observed (April 2026; day approximate)
- Tactical shift to LUNCHPOKE malicious Notepad++ plugin + BURNYBEAR + MATCHBOIL.V2 delivery chain (July 2026; day approximate)
- GuardBreaker prompt-injection VBScript conduit for MATCHBOIL observed (September 2026; reportedly discontinued; day approximate)
- TrendAI publishes its four-year analysis of Earth Sirrush, correlating campaigns via shared encryption, WMI queries, signature artifacts and infrastructure.
- The Hacker News publishes reporting on UAC-0099 ASHVEIN RAT campaign against Ukrainian government personnel
Update history for TL-2026-3083
- 2026-10-10 — Earth Sirrush (UAC-0099) Uses PNG Steganography and Malicious Notepad++ Plugins to Deploy Espionage Malware Against Ukraine: What changed No severity, exploitability, status or attribution-confidence change; the update is additive enrichment only. New indicators (12) Behavioral indicators (.library-ms delivery, renamed schtasks.exe), Regery.com registrar, and add
Sources cited for UAC-0099 (Earth Sirrush) Targets Ukrainian Government
- UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
- TrendAI: Earth Sirrush - Russia-aligned intrusion set, 4 years of evolving espionage tooling
- ESET Research: MATCHBOIL - new tricks, same old evil intentions
- Trojanized ESET Installers Drop Kalambur Backdoor (covers ESET APT Activity Report Q2-Q3 2025, UAC-0099 / Sandworm collaboration)
- CERT-UA - Computer Emergency Response Team of Ukraine
- MITRE ATT&CK - Sandworm Team (G0034)
Detection coverage for TL-2026-3083
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3083 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-3083
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.