# UAC-0099 (Earth Sirrush) Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

> Russia-aligned UAC-0099 (tracked by TrendAI as Earth Sirrush, formerly SHADOW-EARTH-065) is targeting Ukrainian government personnel with the .NET infostealer/RAT ASHVEIN (developer name TelemetryBrowser), which hides tasking in invisible HTML elements and can use a GitHub-based dead drop resolver as fallback C2. ESET reported that UAC-0099 acted as an initial access broker for Sandworm.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-10T08:33:40.441Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3083
- **ID:** TL-2026-3083
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** UAC-0099 (Russia)
- **Detections:** 9 · **IOCs:** 38 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UAC-0099 is a Russia-aligned intrusion set that CERT-UA first documented in June 2023, with targeting of Ukraine observed since mid-2022. TrendAI tracks the cluster as Earth Sirrush (previously SHADOW-EARTH-065) and describes four years of evolving espionage tooling. Victimology centres on Ukrainian government ministries, the defense forces, the State Border Guard Service, the National Police, tax authorities, the Ministry of Justice, transport/logistics operators and defense supply chain entities. ESET telemetry for the MATCHBOIL loader shows Ukraine-only victims in transportation (Jul-Aug 2025), manufacturing (Dec 2025) and energy (Jun 2026).

ASHVEIN is a .NET infostealer and RAT whose developer-assigned name is TelemetryBrowser ("TelemetryUP" branding appears in its metadata). Capabilities include Chrome credential extraction (via DPAPI) and Firefox profile data theft, GDI-based screenshot capture, file enumeration and retrieval, a PowerShell remote shell, WMI-based system fingerprinting and encrypted C2. Per TrendAI, ASHVEIN hides tasking inside invisible HTML elements, and some variants use a GitHub-based dead drop resolver as fallback C2. It checks for analysis tools (Wireshark, IDA, OllyDbg, Fiddler, Process Monitor) and uses XOR-based string encryption shared with MATCHBOIL and DRAGSTARE, as well as anti-debugging and TLS certificate-validation bypass. Five ASHVEIN builds were compiled between 2025-10-08 and 2025-10-23 across three packing variants. It overlaps functionally with the group's DRAGSTARE stealer but uses different packing and separate build environments.

Delivery uses spearphishing, DLL sideloading (FORGECLAMP), VHD containers and dedicated .NET droppers; the AnswerFromPolice dropper embeds a Word decoy impersonating a National Police of Ukraine response. The wider toolset includes the loaders LONEPAGE, SEAGLOW and OVERJAM, the .NET loaders MATCHBOIL (with MATCHBOIL.V2) and MATCHWOK, CINDERBLOT/BadPaw (PNG steganography, March 2026), and a July 2026 chain of the LUNCHPOKE malicious Notepad++ plugin, BURNYBEAR and MATCHBOIL.V2. MATCHBOIL is delivered by spearphishing links to an archive containing a VBScript that downloads and runs the loader. It persists via HKCU Run keys or scheduled tasks and uses a three-request HTTPS C2 exchange with a hex-encoded payload returned in HTML. Newer variants use sandbox checks (Windows Event ID 6013 uptime, OS-install-date age of 10 days or more) and Eziriz .NET Reactor obfuscation.

In September 2026 a malicious VBScript conduit for MATCHBOIL embedded prompts about nuclear weapons ("GuardBreaker") intended to trigger LLM safety mechanisms and disrupt AI-based analysis; it was reportedly discontinued. ESET's APT Activity Report (Q2-Q3 2025, published November 2025) confirmed UAC-0099 performed initial access and handed validated targets to Sandworm. Infrastructure is fronted by Cloudflare, uses Regery.com as registrar and BL Networks (AS399629) backend IPs on BitLaunch VPSes. Severity is analyst-assigned; no CVE is tied to the ASHVEIN chain (CVE-2023-38831 WinRAR exploitation was a 2023 tactic of the group).

## MITRE ATT&CK

- T1583.001 Domains
- T1583.003 Virtual Private Server
- T1587.001 Malware
- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1059.005 Visual Basic
- T1059.001 PowerShell
- T1047 Windows Management Instrumentation
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task
- T1574.001 DLL
- T1140 Deobfuscate/Decode Files or Information
- T1497.001 System Checks
- T1622 Debugger Evasion
- T1036.005 Match Legitimate Resource Name or Location
- T1555.003 Credentials from Web Browsers
- T1082 System Information Discovery
- T1113 Screen Capture
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1102.001 Dead Drop Resolver
- T1573.002 Asymmetric Cryptography
- T1566.001 Phishing
- T1203 Exploitation for Client Execution
- T1574.002 Hijack Execution Flow
- T1027.003 Obfuscated Files or Information
- T1027.009 Obfuscated Files or Information
- T1036.003 Masquerading
- T1218.005 System Binary Proxy Execution
- T1083 File and Directory Discovery
- T1518.001 Software Discovery
- T1090.004 Proxy
- T1105 Ingress Tool Transfer

## Sources

- [UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML](https://thehackernews.com/2026/10/uac-0099-targets-ukrainian-government.html)
- [TrendAI: Earth Sirrush - Russia-aligned intrusion set, 4 years of evolving espionage tooling](https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/earth-sirrush-russia-aligned-intrusion-set-4-years-evolving-espionage-tooling)
- [ESET Research: MATCHBOIL - new tricks, same old evil intentions](https://www.welivesecurity.com/en/eset-research/matchboil-new-tricks-same-old-evil-intentions/)
- [Trojanized ESET Installers Drop Kalambur Backdoor (covers ESET APT Activity Report Q2-Q3 2025, UAC-0099 / Sandworm collaboration)](https://thehackernews.com/2025/11/trojanized-eset-installers-drop.html)
- [CERT-UA - Computer Emergency Response Team of Ukraine](https://cert.gov.ua/)
- [MITRE ATT&CK - Sandworm Team (G0034)](https://attack.mitre.org/groups/G0034/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3083
