Threat reportAPTTL-2026-3083

UAC-0099 (Earth Sirrush) Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

highACTIVE

UAC-0099 (Earth Sirrush) Targets Ukrainian Government (TL-2026-3083), also tracked as TelemetryBrowser, is a high-severity advanced persistent threat campaign, first published 2026-10-09 and last reviewed 2026-10-10. It is attributed to UAC-0099 (Russia) with medium confidence, affects Microsoft Windows, maps to 33 MITRE ATT&CK techniques (T1005, T1027.003, T1027.009), and is covered by 9 detection rules and 38 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
33MITRE ATT&CK
Actors
2UAC-0099
Detection rules
9SPL · KQL · Sigma
IOCs
38Indicators of compromise

Key facts for TL-2026-3083

Threat ID
TL-2026-3083
Also known as
TelemetryBrowser, ASHVEIN, MATCHBOIL, GuardBreaker
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
UAC-0099, Earth Sirrush
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, defense, police - law enforcement, transport, manufacturing, energy, tax-authority, logistics
Target regions
ukraine
Detection rules
9
Indicators of compromise
38
Updates
2026-10-10 · revalidated 1× · latest source

Malware and tooling in UAC-0099 (Earth Sirrush) Targets Ukrainian Government

Malware and tooling: ASHVEIN, BadPaw, DRAGSTARE, FORGECLAMP, MATCHBOIL

How UAC-0099 (Earth Sirrush) Targets Ukrainian Government works

Russia-aligned UAC-0099 (tracked by TrendAI as Earth Sirrush, formerly SHADOW-EARTH-065) is targeting Ukrainian government personnel with the .NET infostealer/RAT ASHVEIN (developer name TelemetryBrowser), which hides tasking in invisible HTML elements and can use a GitHub-based dead drop resolver as fallback C2. ESET reported that UAC-0099 acted as an initial access broker for Sandworm.

UAC-0099 is a Russia-aligned intrusion set that CERT-UA first documented in June 2023, with targeting of Ukraine observed since mid-2022. TrendAI tracks the cluster as Earth Sirrush (previously SHADOW-EARTH-065) and describes four years of evolving espionage tooling. Victimology centres on Ukrainian government ministries, the defense forces, the State Border Guard Service, the National Police, tax authorities, the Ministry of Justice, transport/logistics operators and defense supply chain entities. ESET telemetry for the MATCHBOIL loader shows Ukraine-only victims in transportation (Jul-Aug 2025), manufacturing (Dec 2025) and energy (Jun 2026).

ASHVEIN is a .NET infostealer and RAT whose developer-assigned name is TelemetryBrowser ("TelemetryUP" branding appears in its metadata). Capabilities include Chrome credential extraction (via DPAPI) and Firefox profile data theft, GDI-based screenshot capture, file enumeration and retrieval, a PowerShell remote shell, WMI-based system fingerprinting and encrypted C2. Per TrendAI, ASHVEIN hides tasking inside invisible HTML elements, and some variants use a GitHub-based dead drop resolver as fallback C2. It checks for analysis tools (Wireshark, IDA, OllyDbg, Fiddler, Process Monitor) and uses XOR-based string encryption shared with MATCHBOIL and DRAGSTARE, as well as anti-debugging and TLS certificate-validation bypass. Five ASHVEIN builds were compiled between 2025-10-08 and 2025-10-23 across three packing variants. It overlaps functionally with the group's DRAGSTARE stealer but uses different packing and separate build environments.

Delivery uses spearphishing, DLL sideloading (FORGECLAMP), VHD containers and dedicated .NET droppers; the AnswerFromPolice dropper embeds a Word decoy impersonating a National Police of Ukraine response. The wider toolset includes the loaders LONEPAGE, SEAGLOW and OVERJAM, the .NET loaders MATCHBOIL (with MATCHBOIL.V2) and MATCHWOK, CINDERBLOT/BadPaw (PNG steganography, March 2026), and a July 2026 chain of the LUNCHPOKE malicious Notepad++ plugin, BURNYBEAR and MATCHBOIL.V2. MATCHBOIL is delivered by spearphishing links to an archive containing a VBScript that downloads and runs the loader. It persists via HKCU Run keys or scheduled tasks and uses a three-request HTTPS C2 exchange with a hex-encoded payload returned in HTML. Newer variants use sandbox checks (Windows Event ID 6013 uptime, OS-install-date age of 10 days or more) and Eziriz .NET Reactor obfuscation.

In September 2026 a malicious VBScript conduit for MATCHBOIL embedded prompts about nuclear weapons ("GuardBreaker") intended to trigger LLM safety mechanisms and disrupt AI-based analysis; it was reportedly discontinued. ESET's APT Activity Report (Q2-Q3 2025, published November 2025) confirmed UAC-0099 performed initial access and handed validated targets to Sandworm. Infrastructure is fronted by Cloudflare, uses Regery.com as registrar and BL Networks (AS399629) backend IPs on BitLaunch VPSes. Severity is analyst-assigned; no CVE is tied to the ASHVEIN chain (CVE-2023-38831 WinRAR exploitation was a 2023 tactic of the group).

MITRE ATT&CK techniques used in TL-2026-3083

Collection

T1005 Data from Local System; T1113 Screen Capture

Defense Evasion

T1027.003 Obfuscated Files or Information; T1027.009 Obfuscated Files or Information; T1036.003 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.005 System Binary Proxy Execution; T1497.001 System Checks; T1574.001 DLL; T1622 Debugger Evasion

Execution

T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.005 Visual Basic; T1203 Exploitation for Client Execution; T1204.002 Malicious File

Persistence

T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder; T1574.002 Hijack Execution Flow

Command and Control

T1071.001 Web Protocols; T1090.004 Proxy; T1102.001 Dead Drop Resolver; T1105 Ingress Tool Transfer; T1573.002 Asymmetric Cryptography

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1518.001 Software Discovery

Credential Access

T1555.003 Credentials from Web Browsers

Initial Access

T1566.001 Phishing; T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1583.003 Virtual Private Server; T1587.001 Malware

Affected products and versions in UAC-0099 (Earth Sirrush) Targets Ukrainian Government

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints used by Ukrainian government and defense-sector personnel

Remediation for UAC-0099 (Earth Sirrush) Targets Ukrainian Government

Immediate actions

  • Block the listed domains and BL Networks IPs at DNS/proxy/firewall and hunt for historical connections
  • Hunt for Global\PlannerAssistant mutex, %LOCALAPPDATA%\DeviceMonitor, MeowCheck and SMTPClient directories, and scheduled tasks UpdateCheckers\DailyPlanner, MailClient\Checker and Updates\CheckTask
  • Alert on VBScript or archive execution from mail-linked downloads and on mounting of VHD files from user-writable paths
  • Alert on new files in C:\Users\Public\Libraries\ and on renamed copies of schtasks.exe
  • Reset credentials stored in Chrome and Firefox on any suspected host

Workarounds

  • Restrict outbound access to github.com raw content from non-developer hosts where feasible
  • Disable Windows Script Host for users without a business need

Longer-term hardening

  • Block or restrict VHD mounting and script host execution (wscript/cscript) for standard users
  • Deploy EDR with .NET behavioral and WMI-query detection
  • Do not rely solely on LLM-based analysis of scripts; sanitize or segregate untrusted script content from AI triage prompts
  • Train Ukrainian government and defense-sector staff on police/border-guard/tax-authority themed lures

Timeline of UAC-0099 (Earth Sirrush) Targets Ukrainian Government

  • UAC-0099 targeting of Ukraine begins (mid-2022 per CERT-UA; month approximate)
  • Earth Sirrush used WinRAR CVE-2023-38831 via the OVERJAM Go loader in 2023 (month approximate).
  • CERT-UA initially documents UAC-0099 (June 2023; day approximate)
  • Earliest MATCHBOIL compilation timestamps (April 2024; day approximate)
  • MATCHBOIL first publicly documented by CERT-UA after July-August 2025 ESET telemetry detections against Ukrainian transportation companies (day approximate)
  • Five ASHVEIN builds compiled between 2025-10-08 and 2025-10-23 across three packing variants
  • ESET APT Activity Report (Q2-Q3 2025) identifies UAC-0099 as initial access broker handing targets to Sandworm (month approximate)
  • C2 domain virtualdailyplanner.pro first seen
  • C2 domain flycloud-service.com (64.95.10.223) first seen; CINDERBLOT/BadPaw PNG steganography campaign observed in March 2026
  • MATCHBOIL.V2 DLL variant with OS-install-date virtual environment check observed (April 2026; day approximate)
  • Tactical shift to LUNCHPOKE malicious Notepad++ plugin + BURNYBEAR + MATCHBOIL.V2 delivery chain (July 2026; day approximate)
  • GuardBreaker prompt-injection VBScript conduit for MATCHBOIL observed (September 2026; reportedly discontinued; day approximate)
  • TrendAI publishes its four-year analysis of Earth Sirrush, correlating campaigns via shared encryption, WMI queries, signature artifacts and infrastructure.
  • The Hacker News publishes reporting on UAC-0099 ASHVEIN RAT campaign against Ukrainian government personnel

Update history for TL-2026-3083

Sources cited for UAC-0099 (Earth Sirrush) Targets Ukrainian Government

Detection coverage for TL-2026-3083

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3083 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
38 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-3083

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats