Earth Sirrush Uses PNG Steganography and Malicious Notepad++ Plugins to Deploy Espionage Malware
Russia-aligned Earth Sirrush hides espionage malware in PNGs and Notepad++ plugins against Ukrainian government and defense targets.
Earth Sirrush, overlapping CERT-UA's UAC-0099 and previously tracked as SHADOW-EARTH-065, has targeted Ukrainian government, defense, border, and logistics organizations since at least 2022. TrendAI traced more than 10 malware families through July 2026, including PNG steganography campaigns CINDERBLOT/BadPaw, the LUNCHPOKE Notepad++ plugin, loaders BURNYBEAR and MATCHBOIL.V2, and the ASHVEIN stealer and RAT. Earlier activity exploited WinRAR CVE-2023-38831; newer chains use phishing, scheduled tasks, and DLL proxying. ASHVEIN steals Chrome and Firefox credentials, captures screenshots, and runs remote PowerShell.