Back to Intelligence

UAC-0099 ASHVEIN RAT: Detecting HTML-Weaponized C2 and .NET Infostealer Activity Against Government Targets

SA
Security Arsenal Team
October 8, 2026
13 min read

Security researchers at TrendAI have attributed a previously undocumented .NET infostealer and remote access trojan — codenamed ASHVEIN — to the Russia-aligned threat actor tracked as UAC-0099 (also tracked as Earth Sirrush, formerly SHADOW-EARTH-065). The malware is being actively deployed in targeted attacks against Ukrainian government personnel, and its most notable characteristic is its command-and-control (C2) design: operator instructions are embedded inside HTML content, allowing malicious traffic to blend in with ordinary web browsing.

This is not a theoretical threat. ASHVEIN is in-the-wild, purpose-built espionage tooling from an actor with a sustained operational focus on Ukrainian state entities. While the current campaign is geographically and organizationally scoped, the tradecraft — .NET payloads, HTML-sourced tasking, and infostealer-plus-RAT dual functionality — is directly portable to any target set. Defenders supporting government, defense-industrial-base, diplomatic, or NGO-adjacent organizations should treat this as a live detection engineering task, not a curiosity.

Technical Analysis: How ASHVEIN Works

Threat Actor Profile

UAC-0099 has a documented history of spear-phishing operations against Ukrainian state bodies, typically using lure documents themed around government business, official correspondence, and current events. The group consistently favors lightweight, quickly iterated tooling — which is precisely what ASHVEIN represents: a new implant family built to evade existing signatures against their earlier malware.

The ASHVEIN Implant

Based on TrendAI's reporting, ASHVEIN exhibits the following characteristics relevant to defenders:

  • Written in .NET: The implant is a managed-code executable. This matters for detection because .NET malware frequently arrives obfuscated, is often delivered as a small loader, and may execute in-memory via legitimate .NET framework hosts or script interpreters rather than dropping a large standalone binary.
  • Dual capability — infostealer and RAT: It harvests credentials, browser data, and host information (infostealer function) while also accepting operator tasking for command execution, file manipulation, and follow-on payload delivery (RAT function). Expect outbound data staging in addition to C2 polling.
  • HTML-embedded C2: Rather than beaconing to an obvious C2 endpoint with structured API calls, ASHVEIN retrieves operator commands concealed within HTML content. From a network defender's perspective, this makes the traffic look like ordinary HTTP(S) GET requests returning web pages. The implant parses tasking out of the returned HTML — meaning the C2 channel can ride on compromised legitimate sites, paste-style services, or web infrastructure that is not blocklisted.
  • Targeted delivery: Current use is against Ukrainian government personnel, consistent with spear-phishing as the initial access vector, likely involving malicious attachments or links that lead to HTML-based content — fitting the actor's established pattern of HTML smuggling and HTML/HTA-style lures.

Exploitation Status

This is confirmed active exploitation by a named state-aligned actor in a live conflict context. No CVE is associated with this campaign — it relies on social engineering and commodity initial-access techniques rather than a software vulnerability. It is not currently on CISA KEV because there is no underlying vulnerability; the defensive burden falls entirely on detection of delivery, execution, and C2 behavior.

Why the HTML C2 Channel Matters to Your SOC

The HTML tasking mechanism is the operationally significant detail. It defeats three common defensive assumptions:

  1. Domain/IP reputation alone won't save you. If the commands are embedded in pages hosted on legitimate or freshly compromised infrastructure, threat-intel blocklists will lag the campaign.
  2. Payload-inspecting proxies see benign-looking HTML. The returned content is structured to look like a normal web page.
  3. Beaconing intervals look like browsing. Periodic HTTP(S) requests from a user-context process to web-hosted content are one of the noisiest parts of any environment.

Detection has to anchor on the process making the requests and the context of delivery — not the network destination.

Detection & Response

The detection strategy below layers three hypotheses: (1) delivery via HTML/HTA content that spawns script interpreters, (2) execution of .NET payloads from user-writable or unexpected locations, and (3) unusual processes making HTTP(S) requests consistent with C2 polling. None of these should fire broadly in a well-managed environment — if they do, that is itself an investigation.

SIGMA Rules

YAML
---
title: HTML or HTA File Spawning Script Interpreter or Shell
description: Detects HTML/HTA content (consistent with UAC-0099 lure and HTML-smuggling tradecraft delivering ASHVEIN) executing script interpreters or command shells. Legitimate browsers render HTML; HTML files do not legitimately spawn cmd, PowerShell, wscript, or mshta in typical user workflows.
references:
  - https://thehackernews.com/2026/10/uac-0099-targets-ukrainian-government.html
  - https://attack.mitre.org/techniques/T1204/002/
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/10/21
status: experimental
tags:
  - attack.execution
  - attack.t1204.002
  - attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection_parents:
    ParentImage|endswith:
      - '\mshta.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\hh.exe'
  selection_children:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\msbuild.exe'
      - '\regasm.exe'
      - '\regsvcs.exe'
  condition: all of selection_*
falsepositives:
  - Rare legacy enterprise help-file or HTA administrative tools
level: high
---
title: Suspicious .NET Payload Execution From User-Writable Directories
description: Detects execution of unsigned-style .NET tooling and executables from user profile paths (AppData, Temp, Downloads, Public), consistent with ASHVEIN's .NET implant staging. Also covers inline .NET compilation hosts abused for fileless execution.
references:
  - https://thehackernews.com/2026/10/uac-0099-targets-ukrainian-government.html
  - https://attack.mitre.org/techniques/T1218/
  - https://attack.mitre.org/techniques/T1140/
author: Security Arsenal
date: 2026/10/21
status: experimental
tags:
  - attack.defense_evasion
  - attack.t1218
  - attack.t1140
logsource:
  category: process_creation
  product: windows
detection:
  selection_path:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\Downloads\'
      - '\Users\Public\'
  selection_dotnet_hosts:
    Image|endswith:
      - '\regasm.exe'
      - '\regsvcs.exe'
      - '\msbuild.exe'
      - '\csc.exe'
      - '\vbc.exe'
      - '\installutil.exe'
  selection_encoded_cli:
    CommandLine|contains:
      - '-enc'
      - '-EncodedCommand'
      - 'FromBase64String'
      - 'Reflection.Assembly'
      - 'Assembly.Load'
  condition: selection_path or (selection_dotnet_hosts and selection_encoded_cli)
falsepositives:
  - Developer workstations compiling .NET code; exclude known dev paths
level: high
---
title: Non-Browser Process Making Repeated HTTP Requests to Web Content
description: Detects non-browser processes establishing outbound HTTP/HTTPS connections on standard web ports, consistent with ASHVEIN polling HTML-hosted C2 tasking. Baseline known update services and EDR telemetry before enabling at high sensitivity.
references:
  - https://thehackernews.com/2026/10/uac-0099-targets-ukrainian-government.html
  - https://attack.mitre.org/techniques/T1071/001/
  - https://attack.mitre.org/techniques/T1102/
author: Security Arsenal
date: 2026/10/21
status: experimental
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.t1102
logsource:
  category: network_connection
  product: windows
detection:
  selection_ports:
    DestinationPort:
      - 80
      - 443
  selection_process:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\mshta.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\regasm.exe'
      - '\regsvcs.exe'
      - '\msbuild.exe'
  filter_browsers:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\firefox.exe'
      - '\iexplore.exe'
  condition: selection_ports and selection_process and not filter_browsers
falsepositives:
  - PowerShell update/bootstrap scripts in managed environments
  - Software deployment tooling
level: medium

KQL Hunt — Microsoft Sentinel / Defender

This query hunts the full chain: HTML/HTA file creation in user-controlled locations, followed by script-interpreter or .NET-host execution, and correlates with non-browser outbound web connections that would represent HTML-tasked C2 polling.

KQL — Microsoft Sentinel / Defender
// ASHVEIN / UAC-0099 hunt: HTML lure execution + non-browser HTTP(S) C2 polling
let Lookback = 14d;
let HtmlArtifacts = DeviceFileEvents
| where TimeGenerated > ago(Lookback)
| where FileName endswith ".html" or FileName endswith ".hta"
| where FolderPath has_any ("\\Temp\\", "\\Downloads\\", "\\AppData\\", "\\Public\\")
| project DeviceName, FileCreated=TimeGenerated, FolderPath, FileName, InitiatingProcessFileName, InitiatingProcessCommandLine;
let ScriptExec = DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName in~ ("powershell.exe", "pwsh.exe", "mshta.exe", "wscript.exe", "cscript.exe", "rundll32.exe", "regsvr32.exe", "msbuild.exe", "regasm.exe", "regsvcs.exe")
| where InitiatingProcessFileName in~ ("mshta.exe", "wscript.exe", "cscript.exe", "hh.exe", "chrome.exe", "msedge.exe", "outlook.exe")
   or ProcessCommandLine has_any ("FromBase64String", "Assembly.Load", "-enc", "WebClient", "DownloadString")
| project DeviceName, ExecTime=TimeGenerated, FileName, ProcessCommandLine, InitiatingProcessFileName;
let C2Traffic = DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemotePort in (80, 443)
| where InitiatingProcessFileName !in~ ("chrome.exe", "msedge.exe", "firefox.exe", "iexplore.exe", "svchost.exe", "msmpeng.exe")
| where InitiatingProcessFileName in~ ("powershell.exe", "pwsh.exe", "rundll32.exe", "regsvr32.exe", "mshta.exe", "wscript.exe", "msbuild.exe", "regasm.exe", "regsvcs.exe")
| summarize Connections=count(), Destinations=dcount(RemoteIP), RemoteIPs=make_set(RemoteIP, 10), RemoteUrls=make_set(RemoteUrl, 10) by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine
| where Destinations >= 1;
HtmlArtifacts
| join kind=inner ScriptExec on DeviceName
| join kind=leftouter C2Traffic on DeviceName
| project DeviceName, FileCreated, FolderPath, FileName, ExecTime, FileName1, ProcessCommandLine, Destinations, RemoteIPs, RemoteUrls
| order by DeviceName asc, FileCreated asc

Tune the InitiatingProcessFileName !in~ exclusion list against your own telemetry baseline — add known software updaters and management agents in your environment, but investigate anything making repeated connections to a small set of destinations on a timer-like cadence.

Velociraptor VQL Hunt

This artifact sweeps endpoints for the endpoint-side artifacts of the campaign: recently created HTML/HTA files in user-writable paths, suspicious processes running from those paths, and Run-key persistence entries pointing at user profile locations.

VQL — Velociraptor
-- ASHVEIN / UAC-0099 endpoint sweep: HTML lures, user-dir execution, Run-key persistence
-- Artifact: Custom.Hunt.ASHVEIN.EndpointSweep

LET html_lures = SELECT FullPath AS LurePath, Size, Mtime, Btime
FROM glob(globs=['C:/Users/*/Downloads/*.html', 'C:/Users/*/Downloads/*.hta',
                 'C:/Users/*/AppData/Local/Temp/*.html', 'C:/Users/*/AppData/Local/Temp/*.hta',
                 'C:/Users/Public/*.html', 'C:/Users/Public/*.hta'])
WHERE Btime > now() - 1209600

LET suspicious_procs = SELECT Pid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Exe =~ '(?i)\\(AppData|Temp|Downloads|Public)\\'
   OR CommandLine =~ '(?i)(FromBase64String|Assembly\.Load|DownloadString|WebClient)'

LET run_keys = SELECT FullPath AS RegPath, Name, value.description AS ValueData
FROM glob(globs=['HKEY_USERS/*/Software/Microsoft/Windows/CurrentVersion/Run/*'],
          accessor='registry')
WHERE to_dict(item={
  'Path': RegPath,
  'Name': Name
}) AND ValueData =~ '(?i)(\\AppData\\|\\Temp\\|\\Public\\|\.hta|mshta|powershell)'

SELECT * FROM html_lures
UNION ALL
SELECT * FROM suspicious_procs

Note: adapt the UNION if your Velociraptor version complains about schema mismatch — run each LET block as a separate artifact in the hunt if needed. The Run-key section specifically catches persistence pointing at user-profile payloads, which is where a lightweight .NET implant like ASHVEIN would most plausibly survive reboot.

Remediation and Hardening Script

This PowerShell script performs three functions: (1) audits for execution artifacts consistent with the campaign, (2) checks persistence locations, and (3) applies hardening controls that break the delivery and execution chain. Run elevated. Review output before applying hardening changes in production — test ASR rules in audit mode first.

PowerShell
# ASHVEIN / UAC-0099 — Audit and Harden (run as Administrator)
# 1. AUDIT: Recent HTML/HTA files in user-writable paths
Write-Host "[AUDIT] Recent HTML/HTA files in user-writable locations:" -ForegroundColor Cyan
$cutoff = (Get-Date).AddDays(-14)
Get-ChildItem -Path "$env:SystemDrive\Users" -Include *.html,*.hta -Recurse -ErrorAction SilentlyContinue |
  Where-Object { $_.CreationTime -gt $cutoff -and $_.FullName -match 'Temp|Downloads|Public' } |
  Select-Object FullName, CreationTime, Length | Format-Table -AutoSize

# 2. AUDIT: Run-key persistence pointing at user profile paths
Write-Host "[AUDIT] Suspicious Run-key persistence entries:" -ForegroundColor Cyan
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
             'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($key in $runKeys) {
  if (Test-Path $key) {
    (Get-ItemProperty $key).PSObject.Properties |
      Where-Object { $_.Value -match 'AppData|Temp|Public|\.hta|mshta|powershell' } |
      Select-Object Name, Value
  }
}

# 3. AUDIT: Non-browser processes with recent outbound web connections
Write-Host "[AUDIT] Non-browser processes with established 80/443 connections:" -ForegroundColor Cyan
Get-NetTCPConnection -State Established -RemotePort 80,443 -ErrorAction SilentlyContinue |
  ForEach-Object {
    $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
    if ($p -and $p.ProcessName -notmatch '^(chrome|msedge|firefox|iexplore|svchost|msedge)$') {
      [PSCustomObject]@{ Process=$p.ProcessName; PID=$_.OwningProcess; RemoteIP=$_.RemoteAddress; RemotePort=$_.RemotePort }
    }
  } | Format-Table -AutoSize

# 4. HARDEN: Enable Attack Surface Reduction rules (AUDIT mode first — validate, then set to 1/Block)
# Blocks Office child processes and executable content from email clients/webmail
$asrRules = @{
  'D4F940AB-401B-4EFC-AADC-AD5F3C50688A' = 1  # Block Office apps from creating child processes
  'BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550' = 1  # Block executable content from email client and webmail
  '92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B' = 1  # Block Win32 API calls from Office macros
  '7674BA52-37EB-4A4F-A9A1-F0F9A1619A2C' = 1  # Block abuse of exploited vulnerable signed drivers (optional)
}
foreach ($rule in $asrRules.GetEnumerator()) {
  Add-MpPreference -AttackSurfaceReductionRules_Ids $rule.Key -AttackSurfaceReductionRules_Actions $rule.Value
  Write-Host "[HARDEN] ASR rule $($rule.Key) set to action $($rule.Value)" -ForegroundColor Green
}

# 5. HARDEN: Disable mshta.exe handling of .hta via file association warning (defense-in-depth)
# Consider an AppLocker/WDAC policy to block mshta.exe for standard users instead where feasible
Write-Host "[HARDEN] Recommend: Deploy AppLocker/WDAC rule blocking mshta.exe, wscript.exe for standard users" -ForegroundColor Yellow

# 6. HARDEN: Enable PowerShell Script Block Logging and Module Logging for .NET reflection detection
New-Item -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Force | Out-Null
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Name 'EnableScriptBlockLogging' -Value 1
Write-Host "[HARDEN] PowerShell Script Block Logging enabled" -ForegroundColor Green

# 7. HARDEN: Enforce SmartScreen for files and Edge
Set-MpPreference -EnableSmartScreen $true -ErrorAction SilentlyContinue
New-Item -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\System' -Force | Out-Null
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\System' -Name 'EnableSmartScreen' -Value 1
Write-Host "[HARDEN] SmartScreen enforcement applied" -ForegroundColor Green

Remediation

There is no patch for this threat — it is a social-engineering-delivered implant, not a vulnerability exploit. Remediation is therefore layered across email, endpoint, and network controls:

  1. Email and delivery layer

    • Block or quarantine .html and .hta attachments at the email gateway, or rewrite them to force sandbox detonation before delivery. HTML attachments have almost no legitimate business function in government workflows and are the primary vehicle for this actor's lures.
    • Enable URL rewriting and time-of-click protection for links in inbound mail, especially messages impersonating government correspondence.
    • Strip or neutralize embedded scripts in inbound HTML email bodies.
  2. Endpoint controls

    • Deploy the ASR rules in the script above — start in audit mode, validate over 7–14 days, then enforce block mode.
    • Use AppLocker or WDAC to deny mshta.exe, wscript.exe, and unsigned executables in user-writable directories (%TEMP%, %APPDATA%, %USERPROFILE%\Downloads, C:\Users\Public) for standard users.
    • Ensure Microsoft Defender (or your EDR) has cloud-delivered protection and tamper protection enabled; confirm .NET script and AMSI integration is functional so reflection-loaded assemblies are scanned.
    • Enable PowerShell Script Block Logging and Module Logging fleet-wide and ship the logs to your SIEM — this is your highest-fidelity telemetry source for .NET payload staging.
  3. Network controls

    • Because ASHVEIN's C2 rides inside HTML, egress filtering by destination reputation is necessary but insufficient. Add detection for non-browser processes making periodic HTTP(S) requests, and alert on hosts pulling HTML content-type responses at fixed intervals from single destinations.
    • Where TLS inspection is in place, alert on HTML responses with anomalous structure (e.g., pages containing large encoded blobs in comments or hidden elements) requested by non-browser user agents.
  4. Credential exposure response

    • ASHVEIN is an infostealer: assume any host confirmed to have run the implant has had browser-stored credentials, session tokens, and files harvested. On confirmed infection: isolate the host, force password resets for all accounts that have authenticated from it, revoke active sessions and refresh tokens (especially for Microsoft 365 / cloud SSO), and review mailbox rules and OAuth grants for the affected users.
    • Enforce phishing-resistant MFA (FIDO2/passkeys) for government and administrative accounts — this blunts the value of harvested credentials.
  5. Threat intelligence and monitoring

    • Subscribe to TrendAI/Trend Micro's Earth Sirrush reporting and CERT-UA advisories for UAC-0099 indicators (CERT-UA publishes IOCs for this actor's campaigns with short turnaround).
    • Feed confirmed IOCs into your blocklists, but treat them as perishable — prioritize behavioral detections (the rules above) over hash/IP matching.
    • If your organization has Ukrainian government, defense, diplomatic, or humanitarian-sector partnerships, brief those teams on the current lure themes and establish a rapid reporting channel for suspicious messages.
  6. Validation

    • Run the KQL hunt retroactively across at least 30 days of telemetry. If you operate a SOC for any organization in this actor's targeting footprint, assume you have been phished and hunt accordingly rather than waiting for an alert.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.