Earth Sirrush Espionage Activity May Support Sandworm Operations Against Ukraine
Earth Sirrush has spear-phished Ukrainian government and logistics since 2022, possibly feeding Sandworm.
TrendAI says Russia-aligned Earth Sirrush, also tracked as SHADOW-EARTH-065 and CERT-UA's UAC-0099, has spear-phished Ukrainian government, defense, border, and logistics targets since at least 2022 through July 2026. Early intrusions used archives, HTA files, and WinRAR flaw CVE-2023-38831; later chains added C# tools such as MATCHBOIL and the ASHVEIN stealer-RAT, image steganography in CINDERBLOT, and the LUNCHPOKE Notepad++ plugin. Shared signatures, XOR routines, and Regery-plus-Cloudflare infrastructure tie the clusters together. ESET's view that UAC-0099 may have given Sandworm initial access is presented as a hypothesis, not confirmed control.