Earth Sirrush Uses PNG Steganography and Malicious Notepad++ Plugins to Deploy Espionage Malware
Russia-aligned Earth Sirrush hides espionage malware in PNGs and Notepad++ plugins against Ukrainian government and defense targets.
Earth Sirrush, overlapping CERT-UA's UAC-0099 and previously tracked as SHADOW-EARTH-065, has targeted Ukrainian government, defense, border, and logistics organizations since at least 2022. TrendAI traced more than 10 malware families through July 2026, including PNG steganography campaigns CINDERBLOT/BadPaw, the LUNCHPOKE Notepad++ plugin, loaders BURNYBEAR and MATCHBOIL.V2, and the ASHVEIN stealer and RAT. Earlier activity exploited WinRAR CVE-2023-38831; newer chains use phishing, scheduled tasks, and DLL proxying. ASHVEIN steals Chrome and Firefox credentials, captures screenshots, and runs remote PowerShell.
- Earth Sirrush overlaps UAC-0099 and has targeted Ukraine since at least 2022.
- 2026 campaigns hide payloads in PNG images and a malicious Notepad++ plugin, LUNCHPOKE.
- ASHVEIN steals browser credentials, takes screenshots, and executes remote PowerShell.
- Earlier intrusions exploited WinRAR flaw CVE-2023-38831.
- TrendAI linked over ten malware families through shared code and infrastructure.
Vulnerabilities mentionedAll →
- CVE-2023-388317.8100%Code Execution in RARLAB WinRAR via Crafted ZIP File/Folder Name Confusionpublished · RARLAB WinRAR KEV ransomware PoC ×4
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | cyberflysystems.com | compromise (IoCs):- Type Indicator Description Domain order.cyberflysystems[.]com Fraudulent drone-parts download page displaying a fake an |
| domain | regery.com | metadata and related infrastructure. Infrastructure context Regery.com Legitimate registrar used for many confirmed command-and-co |
Full article935 words · extracted from cybersecuritynews.com · click to collapse
Earth Sirrush is hiding espionage malware inside PNG images and malicious Notepad++ plugins to compromise Ukrainian organizations.
The Russia-aligned group has targeted government agencies, defense organizations, border guards, and logistics operators since at least 2022, repeatedly changing its tools to maintain access across the country’s wartime supply networks.
The attacks begin with carefully tailored phishing messages, malicious archives, and documents impersonating trusted institutions.
Earlier campaigns also exploited the WinRAR vulnerability CVE-2023-38831, while newer operations combine convincing download pages with concealed payloads and software components that appear legitimate.
Researchers from TrendAI identified links across these campaigns, tracing the activity from 2022 through July 2026.
TrendAI said in a report shared with Cyber Security News (CSN) that the group developed more than 10 malware families while retaining recognizable development and infrastructure patterns.
Previously tracked as SHADOW-EARTH-065, Earth Sirrush overlaps with CERT-UA’s UAC-0099 designation. Its history of evolving UAC-0099 attack methods provides context for the latest findings, which point to sustained intelligence gathering rather than quick theft followed by an immediate departure.
Earth Sirrush Uses PNG Steganography and Malicious Notepad++ Plugins
In 2026, the group expanded its use of steganography, a technique that hides information inside ordinary files. One campaign, tracked as CINDERBLOT and also known as BadPaw, used phishing messages impersonating Ukraine’s State Border Guard Service to draw recipients into the infection chain.
A later operation impersonated a drone parts company and directed victims to a professional-looking website. A fraudulent antivirus verification message encouraged downloads of weaponized ZIP archives, illustrating how familiar commercial branding can make a malicious delivery page appear trustworthy to prospective buyers.
.webp)
The attackers concealed payloads inside PNG images and used scheduled tasks to launch them. Similar PNG malware concealment techniques have appeared in other campaigns, but Earth Sirrush used multiple approaches, including appending code after image data and extracting hidden content from pixels with PowerShell.
In July 2026, CERT-UA documented another chain beginning with LUNCHPOKE, a malicious Notepad++ plugin. Through DLL proxying, the plugin runs attacker code when the editor starts, making abuse of Notepad++ plugins a delivery route that relies on familiar software rather than an obviously suspicious application.
LUNCHPOKE deploys BURNYBEAR, a .NET loader, and MATCHBOIL.V2, an updated loader with stronger encryption and revised concealment.
Components reside in randomized, writable directories, while renamed Windows scheduling utilities establish frequent execution; a parallel image-based chain uses Windows startup settings to preserve access.
Espionage and Defenses
Among the group’s newer tools is ASHVEIN, a previously undocumented .NET information stealer and remote access trojan.
Its capabilities include stealing Chrome and Firefox credentials, capturing screenshots, retrieving files, running remote PowerShell commands, and collecting identifying information about the compromised computer.
ASHVEIN encrypts communications and checks for tools commonly used to investigate malware. It also hides instructions inside invisible webpage elements, while some variants use GitHub as a fallback source for server information, providing alternative ways to reconnect when the primary route is unavailable.
.webp)
The findings extend earlier reporting on UAC-0099 loader delivery chains across Ukrainian targets. Researchers connected changing malware families through shared encryption code, identical system-identification queries, reused signature artifacts, recurring development traces, and infrastructure relationships, rather than treating any single clue as decisive evidence.
Many confirmed command servers used the same registrar and Cloudflare fronting, with backend systems concentrated in one hosting network.
In one observed case, scheduled-task persistence preserved an implant through a month without server communication, underscoring the group’s ability to maintain long-term footholds.
TrendAI recommends blocking confirmed malicious infrastructure while treating shared backend systems as supporting evidence, not proof by themselves.
Defenders should investigate unusual plugin loading, renamed scheduling utilities, executable creation in writable directories, suspicious virtual disk mounts, and executable code appended to image files.
The report also recommends PowerShell logging and restrictions, auditing access to protected credentials, and monitoring unusual browser-data access.
Staff should learn to recognize targeted institutional impersonation, verify incoming document signatures, and watch for concealed file extensions, particularly across government, defense, border security, and logistics organizations, where convincing correspondence can conceal a persistent compromise.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.