Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
SonicWall Patches Critical Pre-Auth SSRF (CVE-2024-XXXX) in SMA1000
October 7, 2026
Hackers Breach South Korean Churches, Exposing 1 Million Members’ Data
October 7, 2026
FBI Warns of Critical FortiBleed Attacks Exploiting Fortinet Firewalls and VPNs
October 7, 2026
Home/Threats/Earth Sirrush Uses Notepad++ Plugins and Steganography for Espionage
Threats

Earth Sirrush Uses Notepad++ Plugins and Steganography for Espionage

Key Takeaways The Russia-aligned threat group Earth Sirrush (UAC-0099) is actively deploying espionage malware against Ukrainian entities. Attackers leverage sophisticated techniques, including...

Emy Elsamnoudy
Emy Elsamnoudy
October 7, 2026 4 Min Read
3 0

Key Takeaways

  • The Russia-aligned threat group Earth Sirrush (UAC-0099) is actively deploying espionage malware against Ukrainian entities.
  • Attackers leverage sophisticated techniques, including steganography within PNG images and malicious Notepad++ plugins, to deliver their payloads.
  • Targets include government, defense, border security, and logistics organizations, indicating a strategic focus on wartime supply networks.
  • The group employs a variety of custom malware families, such as ASHVEIN, BURNYBEAR, and MATCHBOIL.V2, demonstrating continuous tool evolution.
  • Initial compromise often relies on expertly crafted phishing campaigns, weaponized archives, and exploitation of vulnerabilities like CVE-2023-38831.

The Russia-aligned threat group known as Earth Sirrush, also identified as UAC-0099 by CERT-UA and previously as SHADOW-EARTH-065, is engaged in a persistent espionage campaign targeting critical Ukrainian organizations. This advanced persistent threat (APT) has been observed employing innovative techniques, including embedding malware within seemingly innocuous PNG images and distributing malicious plugins for the popular text editor Notepad++, according to recent findings.

Table Of Content

  • Key Takeaways
  • Advanced Tactics: Steganography and Malicious Plugins
  • PNG Steganography
  • Notepad++ Plugin Abuse
  • Espionage Capabilities and Defense Mechanisms
  • ASHVEIN Information Stealer
  • What You Should Do

Since at least 2022, Earth Sirrush has focused its efforts on Ukrainian government agencies, defense contractors, border security forces, and logistics operators. This sustained targeting suggests a strategic objective to maintain access and gather intelligence across the nation’s vital supply chain networks, adapting its attack methodologies over time to ensure continued infiltration.

The initial phase of these attacks typically involves highly convincing phishing emails, weaponized archival files, and deceptive documents that impersonate legitimate institutions. Earlier campaigns by the group notably exploited the WinRAR vulnerability CVE-2023-38831. More recent operations have shifted to employing convincing download pages that host concealed payloads and seemingly legitimate software components.

TrendAI researchers have meticulously tracked these campaigns from 2022 through July 2026. In a report shared with Cyber Security News (CSN), TrendAI highlighted that the group has developed over ten distinct malware families. Despite this variety, consistent development practices and infrastructure patterns have allowed researchers to link the activities, suggesting a strategy of long-term intelligence gathering rather than opportunistic data exfiltration.

Advanced Tactics: Steganography and Malicious Plugins

PNG Steganography

In 2026, Earth Sirrush significantly escalated its use of steganography, a method of hiding data within other data, typically image or audio files. One notable campaign, dubbed CINDERBLOT (also known as BadPaw), utilized phishing emails impersonating Ukraine’s State Border Guard Service. These emails lured victims into downloading malicious files containing hidden payloads within PNG images. The attackers employed several sophisticated steganographic techniques, including appending malicious code after the image data and leveraging PowerShell to extract hidden content from image pixels.

Another operation involved a highly professional-looking website impersonating a drone parts supplier. This site featured a fraudulent antivirus verification message, coercing users into downloading weaponized ZIP archives. This tactic underscores the group’s ability to leverage familiar commercial branding to enhance the perceived legitimacy of their malicious distribution channels.

Notepad++ Plugin Abuse

More recently, in July 2026, CERT-UA documented a new infection chain originating from LUNCHPOKE, a malicious plugin designed for Notepad++. This plugin exploits DLL proxying, allowing attacker-controlled code to execute automatically when the Notepad++ editor launches. This method leverages trusted software as a covert delivery mechanism, making the malicious activity less conspicuous than traditional suspicious applications.

LUNCHPOKE is responsible for deploying BURNYBEAR, a .NET loader, and MATCHBOIL.V2, an enhanced loader featuring stronger encryption and improved concealment techniques. These malware components are strategically placed in randomized, writable directories on compromised systems, and renamed Windows scheduling utilities are used to ensure persistent and frequent execution. A parallel, image-based infection chain also utilizes Windows startup settings to maintain access, demonstrating a multi-pronged approach to persistence.

Espionage Capabilities and Defense Mechanisms

ASHVEIN Information Stealer

Among the group’s newer arsenal is ASHVEIN, a previously uncataloged .NET-based information stealer and remote access trojan. ASHVEIN is equipped with extensive capabilities, including the theft of credentials from popular web browsers like Chrome and Firefox, screenshot capture, arbitrary file retrieval, remote PowerShell command execution, and comprehensive collection of system identifying information from the compromised machine.

ASHVEIN employs encrypted communications and incorporates checks for common malware analysis tools, complicating detection and forensic efforts. It also hides its command-and-control (C2) instructions within invisible elements of webpages. Some variants even utilize GitHub as a fallback mechanism to retrieve C2 server information, ensuring connectivity even if primary communication channels are disrupted.

The consistent evolution of UAC-0099’s attack methods, as highlighted by TrendAI, points to a sophisticated and determined adversary. Researchers were able to link various malware families through shared encryption algorithms, identical system-identification queries, recurring signature artifacts, consistent development patterns, and interconnected infrastructure. This comprehensive analysis allowed them to establish clear connections across the group’s diverse toolkit.

Analysis of the group’s infrastructure revealed that many confirmed C2 servers shared the same domain registrar and utilized Cloudflare for fronting, with backend systems often clustered within a single hosting network. In one observed incident, a persistent implant remained active for a month without C2 communication, sustained by scheduled tasks, underscoring Earth Sirrush’s capability for long-term operational stealth.

What You Should Do

  • Block Malicious Infrastructure: Immediately block all known malicious domains and IP addresses associated with Earth Sirrush.
  • Monitor for Anomalous Activity: Investigate unusual plugin loading within applications like Notepad++, the presence of renamed scheduling utilities (e.g., schtasks.exe), and executable file creation in non-standard, writable directories (e.g., C:UsersPublicLibraries).
  • Inspect Image Files: Implement solutions to detect executable code appended to image files, particularly PNGs, and monitor for suspicious virtual disk mounts.
  • Enhance PowerShell Security: Enable comprehensive PowerShell logging and enforce strict PowerShell execution policies to prevent unauthorized script execution.
  • Audit Credential Access: Regularly audit access to protected credentials and monitor for unusual attempts to access browser data files like Chrome’s Local State.
  • Security Awareness Training: Educate staff, especially in government, defense, border security, and logistics sectors, on recognizing targeted institutional impersonation, verifying digital document signatures, and identifying concealed file extensions (e.g., .library-ms).
  • Review IoCs: Use the provided <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/00109b96-e316-498c-82cc-1d774ad34395/Earth-Sirrush-Uses-PNG-Steganography-and-Malicious-Notepad-Plugins-to-Deploy-Espionage-Malware.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Checksum-Mode=ENABLED&X-Amz-Credential=ASIA2F3EMEYEZR22J5N2%2F20261007%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20261007T121549Z&X-Amz-Expires=3029&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDic8zKbxYwPS8sgWvc077xfYbaqdHw2%2BcYCeS3Z5qAngIhAIehqL%2FIa6DLN8dDhPNxNWqiaUd6BM%2Fktom6k9AZlssVKoAFCA0QARoMNjk5NzUzMzA5NzA1Igw9fXyBX1j%2BUSEVlz4q3QQCmkTLQSzkCPbWx4FQ31hhLUpoFZUBnf8nqTrGf9gSzNP7OpEuCzQlPzZrj1xfOpIN97xZ%2BBQZ2FZLjren%2FBqu%2B1jjaSiNq7T3%2BUmp6vhwgc1OyxsgIlXIUa6FxPdFZ8GY0thT106z%2FpWVkpZX05afVKTEstmLZs%2Bf9mCc3sOkATPdB01SVNzlMp%2BgFaObQDO77EzzkBLjpFDW7LqIIfoWs5QYFvBTDYfswWmiuPO5rjDtyePTc%2B49HZ%2F%2FYw%2F%2FtwrOBHP%2BKn%2FkpMDAS3BE5V5K%2BqqV2w3heK3XqYmVFyBLN3n1QdlzSA511Z7Pq77llro9sHMY7g5HQETpO0dqnBoNGB7E9cBdsRpZ71JNepNibEmWDUj2Q3EbJZdVjaXevb2DUtOuolD9utVlo5duYX%2FuAvElMkRRDct3nDM21A0QebtlLIMCKwuUiMgzES%2F9KBx4wS0J09FRdUNAQoJzn315rBagqjPZSPl4JR16s5uYY%2BA0BU9kdatzDRPejxeDqFgtX%2BjGj%2FepENAJXQlrolu%2B0Vi%2FDg9MEco%2BQczKBvEDp4ovnsfLok%2BBoNDFweK2DbGLkw7%2Bh8I%2BWdo%2Fh

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    AttackCVEExploitMalwarephishingSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical OpenAI Sandbox Flaw Exposed Paid AI Models

Next Post

Rockstar Games Suffers Data Breach, GTA VI Source Code Stolen

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Rockstar Games Suffers Data Breach, GTA VI Source Code Stolen
October 7, 2026
Earth Sirrush Uses Notepad++ Plugins and Steganography for Espionage
October 7, 2026
Critical OpenAI Sandbox Flaw Exposed Paid AI Models
October 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us