ASHVEIN is a .NET remote access trojan and information stealer used by the Russia-aligned espionage group UAC-0099, also tracked as Earth Sirrush and previously as SHADOW-EARTH-065. Internally called TelemetryBrowser by its developers, it has been deployed against Ukrainian government personnel and targets Windows systems.
ASHVEIN steals credentials from Chrome and Firefox, uses Windows DPAPI for credential access, captures screenshots through GDI, enumerates and retrieves files, executes remote PowerShell commands, and fingerprints compromised systems through WMI queries. These capabilities support credential theft, surveillance, data collection, and interactive remote access.
The malware encrypts command-and-control communications and conceals tasking within invisible HTML elements. Some variants use a GitHub-based dead-drop resolver as a fallback for locating command-and-control servers. It also checks for malware-analysis and monitoring tools, including debuggers and network inspection utilities.
ASHVEIN delivery chains use DLL sideloading, VHD containers, and dedicated .NET droppers. An associated delivery component displays a Microsoft Word decoy impersonating the National Police of Ukraine while deploying malware in the background. Its deployment forms part of Earth Sirrush's broader espionage activity against Ukrainian institutions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ASHVEIN, which its developers internally refer to as "TelemetryBrowser," brings together credential theft, surveillance, and remote-control capabilities.
ASHVEIN, which its developers internally refer to as "TelemetryBrowser," brings together credential theft, surveillance, and remote-control capabilities.
ASHVEIN, which its developers internally refer to as "TelemetryBrowser," brings together credential theft, surveillance, and remote-control capabilities.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET malware used against Ukrainian government personnel. It steals Chrome and Firefox credentials, captures screenshots, enumerates and retrieves files, executes remote PowerShell commands, fingerprints systems, and uses encrypted C2 communications. Tasking is hidden in invisible HTML elements; some variants use a GitHub-based fallback dead-drop resolver. Delivery includes DLL sideloading, VHD containers, and dedicated .NET droppers. Five builds were compiled between October 8 and October 23, 2025.
Steals Chrome and Firefox credentials, captures screenshots, retrieves files, executes remote PowerShell commands, and collects system-identifying information. Encrypts communications, checks for malware-investigation tools, and hides instructions in invisible webpage elements. Some variants retrieve fallback server information from GitHub.
.NET espionage malware that steals Chrome and Firefox credentials, captures screenshots, retrieves files, executes remote PowerShell commands, and gathers computer-identification information. It encrypts communications, checks for malware-analysis tools, and conceals instructions in invisible webpage elements. Some variants retrieve fallback server information from GitHub.
A .NET infostealer and remote access trojan targeting Ukrainian government personnel. It steals Chrome and Firefox credentials using DPAPI, captures screenshots, enumerates and retrieves files, executes PowerShell remote shells, and fingerprints systems through WMI. It uses encrypted command-and-control, hides tasking in invisible HTML elements, detects analysis tools, and sometimes uses a GitHub dead-drop resolver. Delivery methods include DLL sideloading, VHD containers, and dedicated .NET droppers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.