UAC-0099 Deploys ASHVEIN .NET Infostealer Against Ukraine
🛡️ TrendAI attributes a previously undocumented .NET infostealer and RAT named ASHVEIN (aka TelemetryBrowser) to the Russia-aligned actor UAC-0099, used in operations targeting Ukrainian government personnel. The malware combines credential theft from Chrome and Firefox, GDI-based screenshots, file collection, PowerShell remote shells, system fingerprinting, and encrypted C2 communications, with delivery via DLL sideloading, VHD containers, and .NET droppers. UAC-0099 has evolved from PowerShell- and Go-based tools to C# and .NET-protected binaries and has expanded targeting to logistics and civilian infrastructure.
