Earth Sirrush Espionage Activity Targets Ukrainian Government Organizations
TrendAI links Russia-aligned Earth Sirrush, or UAC-0099, to Ukrainian espionage since 2022, including ASHVEIN and a possible Sandworm role.
TrendAI says Russia-aligned Earth Sirrush, also tracked as SHADOW-EARTH-065 and CERT-UA's UAC-0099, has spear-phished Ukrainian government, defense, border, and logistics organizations since at least 2022 through July 2026. Early intrusions used archives, HTA files, and WinRAR flaw CVE-2023-38831; later activity added more than 10 families, including loaders BURNYBEAR and MATCHBOIL (one report says MATCHBOIL.V2), PNG steganography in CINDERBLOT (also called BadPaw), the LUNCHPOKE Notepad++ plugin, and the .NET stealer-RAT ASHVEIN (TelemetryBrowser). ASHVEIN is reported to steal Chrome and Firefox credentials, capture screenshots, collect files, and run PowerShell, with tasking hidden in invisible HTML and a GitHub dead-drop fallback; cited delivery includes phishing, scheduled tasks, DLL proxying or sideloading, VHD containers, and a National Police of Ukraine decoy. Shared code, XOR routines, and infrastructure often using Regery domains, Cloudflare, and BL Networks AS399629 are said to tie the clusters together. Sources differ in emphasis on Sandworm: one presents ESET's view that UAC-0099 may have supplied initial access as an unproven hypothesis, while a later report calls UAC-0099 a possible initial-access broker without confirming control. The newest account also says ESET reported a VBScript embedding a prohibited-weapons prompt meant to trip LLM safety filters and hinder analysis of the MATCHBOIL loader.
- TrendAI attributes Russia-aligned Earth Sirrush (SHADOW-EARTH-065; CERT-UA UAC-0099) to spear-phishing of Ukrainian government, defense, border, and logistics targets from at least 2022 through July 2026.
- Early activity used archives, HTA files, and WinRAR CVE-2023-38831; later chains used phishing, scheduled tasks, and DLL proxying or sideloading.
- TrendAI linked more than 10 families, including loaders BURNYBEAR and MATCHBOIL (one report says MATCHBOIL.V2), CINDERBLOT PNG steganography (also called BadPaw), and the LUNCHPOKE Notepad++ plugin.
- ASHVEIN (TelemetryBrowser), a .NET stealer-RAT, steals Chrome and Firefox credentials, takes screenshots, collects files, and runs PowerShell, hiding tasking in invisible HTML with a GitHub dead-drop fallback.
- The newest report adds delivery via VHD containers and a National Police of Ukraine decoy.
- Shared code, XOR routines, and infrastructure often using Regery domains, Cloudflare, and BL Networks AS399629 are said to connect the clusters.
- ESET's claim that UAC-0099 may have supplied Sandworm with initial access is presented as an unproven hypothesis or possible broker role, not confirmed control.
- ESET also reported a VBScript that embeds a prohibited-weapons prompt intended to trip LLM safety filters and hinder analysis of MATCHBOIL.
Coverage timelineoldest first · each row is one article
- · 1d agoEarth Sirrush Espionage Activity May Support Sandworm Operations Against Ukraine
GBHackers· 78
Earth Sirrush has spear-phished Ukrainian government and logistics since 2022, possibly feeding Sandworm.
- · 1d agoEarth Sirrush Uses PNG Steganography and Malicious Notepad++ Plugins to Deploy Espionage Malware
Cyber Security News· 74
Russia-aligned Earth Sirrush hides espionage malware in PNGs and Notepad++ plugins against Ukrainian government and defense targets.
- · 9h ago
Vulnerabilities in this storyAll →
- CVE-2023-388317.8100%Code Execution in RARLAB WinRAR via Crafted ZIP File/Folder Name Confusionpublished · RARLAB WinRAR KEV ransomware PoC ×4