Earth Sirrush Uses Notepad++ Plugins and Steganography for Espionage
Key Takeaways The Russia-aligned threat group Earth Sirrush (UAC-0099) is actively deploying espionage malware against Ukrainian entities. Attackers leverage sophisticated techniques, including...
Key Takeaways
- The Russia-aligned threat group Earth Sirrush (UAC-0099) is actively deploying espionage malware against Ukrainian entities.
- Attackers leverage sophisticated techniques, including steganography within PNG images and malicious Notepad++ plugins, to deliver their payloads.
- Targets include government, defense, border security, and logistics organizations, indicating a strategic focus on wartime supply networks.
- The group employs a variety of custom malware families, such as ASHVEIN, BURNYBEAR, and MATCHBOIL.V2, demonstrating continuous tool evolution.
- Initial compromise often relies on expertly crafted phishing campaigns, weaponized archives, and exploitation of vulnerabilities like CVE-2023-38831.
The Russia-aligned threat group known as Earth Sirrush, also identified as UAC-0099 by CERT-UA and previously as SHADOW-EARTH-065, is engaged in a persistent espionage campaign targeting critical Ukrainian organizations. This advanced persistent threat (APT) has been observed employing innovative techniques, including embedding malware within seemingly innocuous PNG images and distributing malicious plugins for the popular text editor Notepad++, according to recent findings.
Table Of Content
Since at least 2022, Earth Sirrush has focused its efforts on Ukrainian government agencies, defense contractors, border security forces, and logistics operators. This sustained targeting suggests a strategic objective to maintain access and gather intelligence across the nation’s vital supply chain networks, adapting its attack methodologies over time to ensure continued infiltration.
The initial phase of these attacks typically involves highly convincing phishing emails, weaponized archival files, and deceptive documents that impersonate legitimate institutions. Earlier campaigns by the group notably exploited the WinRAR vulnerability CVE-2023-38831. More recent operations have shifted to employing convincing download pages that host concealed payloads and seemingly legitimate software components.
TrendAI researchers have meticulously tracked these campaigns from 2022 through July 2026. In a report shared with Cyber Security News (CSN), TrendAI highlighted that the group has developed over ten distinct malware families. Despite this variety, consistent development practices and infrastructure patterns have allowed researchers to link the activities, suggesting a strategy of long-term intelligence gathering rather than opportunistic data exfiltration.
Advanced Tactics: Steganography and Malicious Plugins
PNG Steganography
In 2026, Earth Sirrush significantly escalated its use of steganography, a method of hiding data within other data, typically image or audio files. One notable campaign, dubbed CINDERBLOT (also known as BadPaw), utilized phishing emails impersonating Ukraine’s State Border Guard Service. These emails lured victims into downloading malicious files containing hidden payloads within PNG images. The attackers employed several sophisticated steganographic techniques, including appending malicious code after the image data and leveraging PowerShell to extract hidden content from image pixels.
Another operation involved a highly professional-looking website impersonating a drone parts supplier. This site featured a fraudulent antivirus verification message, coercing users into downloading weaponized ZIP archives. This tactic underscores the group’s ability to leverage familiar commercial branding to enhance the perceived legitimacy of their malicious distribution channels.
Notepad++ Plugin Abuse
More recently, in July 2026, CERT-UA documented a new infection chain originating from LUNCHPOKE, a malicious plugin designed for Notepad++. This plugin exploits DLL proxying, allowing attacker-controlled code to execute automatically when the Notepad++ editor launches. This method leverages trusted software as a covert delivery mechanism, making the malicious activity less conspicuous than traditional suspicious applications.
LUNCHPOKE is responsible for deploying BURNYBEAR, a .NET loader, and MATCHBOIL.V2, an enhanced loader featuring stronger encryption and improved concealment techniques. These malware components are strategically placed in randomized, writable directories on compromised systems, and renamed Windows scheduling utilities are used to ensure persistent and frequent execution. A parallel, image-based infection chain also utilizes Windows startup settings to maintain access, demonstrating a multi-pronged approach to persistence.
Espionage Capabilities and Defense Mechanisms
ASHVEIN Information Stealer
Among the group’s newer arsenal is ASHVEIN, a previously uncataloged .NET-based information stealer and remote access trojan. ASHVEIN is equipped with extensive capabilities, including the theft of credentials from popular web browsers like Chrome and Firefox, screenshot capture, arbitrary file retrieval, remote PowerShell command execution, and comprehensive collection of system identifying information from the compromised machine.
ASHVEIN employs encrypted communications and incorporates checks for common malware analysis tools, complicating detection and forensic efforts. It also hides its command-and-control (C2) instructions within invisible elements of webpages. Some variants even utilize GitHub as a fallback mechanism to retrieve C2 server information, ensuring connectivity even if primary communication channels are disrupted.
The consistent evolution of UAC-0099’s attack methods, as highlighted by TrendAI, points to a sophisticated and determined adversary. Researchers were able to link various malware families through shared encryption algorithms, identical system-identification queries, recurring signature artifacts, consistent development patterns, and interconnected infrastructure. This comprehensive analysis allowed them to establish clear connections across the group’s diverse toolkit.
Analysis of the group’s infrastructure revealed that many confirmed C2 servers shared the same domain registrar and utilized Cloudflare for fronting, with backend systems often clustered within a single hosting network. In one observed incident, a persistent implant remained active for a month without C2 communication, sustained by scheduled tasks, underscoring Earth Sirrush’s capability for long-term operational stealth.
What You Should Do
- Block Malicious Infrastructure: Immediately block all known malicious domains and IP addresses associated with Earth Sirrush.
- Monitor for Anomalous Activity: Investigate unusual plugin loading within applications like Notepad++, the presence of renamed scheduling utilities (e.g.,
schtasks.exe), and executable file creation in non-standard, writable directories (e.g.,C:UsersPublicLibraries). - Inspect Image Files: Implement solutions to detect executable code appended to image files, particularly PNGs, and monitor for suspicious virtual disk mounts.
- Enhance PowerShell Security: Enable comprehensive PowerShell logging and enforce strict PowerShell execution policies to prevent unauthorized script execution.
- Audit Credential Access: Regularly audit access to protected credentials and monitor for unusual attempts to access browser data files like Chrome’s
Local State. - Security Awareness Training: Educate staff, especially in government, defense, border security, and logistics sectors, on recognizing targeted institutional impersonation, verifying digital document signatures, and identifying concealed file extensions (e.g.,
.library-ms). - Review IoCs: Use the provided <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/00109b96-e316-498c-82cc-1d774ad34395/Earth-Sirrush-Uses-PNG-Steganography-and-Malicious-Notepad-Plugins-to-Deploy-Espionage-Malware.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Checksum-Mode=ENABLED&X-Amz-Credential=ASIA2F3EMEYEZR22J5N2%2F20261007%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20261007T121549Z&X-Amz-Expires=3029&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDic8zKbxYwPS8sgWvc077xfYbaqdHw2%2BcYCeS3Z5qAngIhAIehqL%2FIa6DLN8dDhPNxNWqiaUd6BM%2Fktom6k9AZlssVKoAFCA0QARoMNjk5NzUzMzA5NzA1Igw9fXyBX1j%2BUSEVlz4q3QQCmkTLQSzkCPbWx4FQ31hhLUpoFZUBnf8nqTrGf9gSzNP7OpEuCzQlPzZrj1xfOpIN97xZ%2BBQZ2FZLjren%2FBqu%2B1jjaSiNq7T3%2BUmp6vhwgc1OyxsgIlXIUa6FxPdFZ8GY0thT106z%2FpWVkpZX05afVKTEstmLZs%2Bf9mCc3sOkATPdB01SVNzlMp%2BgFaObQDO77EzzkBLjpFDW7LqIIfoWs5QYFvBTDYfswWmiuPO5rjDtyePTc%2B49HZ%2F%2FYw%2F%2FtwrOBHP%2BKn%2FkpMDAS3BE5V5K%2BqqV2w3heK3XqYmVFyBLN3n1QdlzSA511Z7Pq77llro9sHMY7g5HQETpO0dqnBoNGB7E9cBdsRpZ71JNepNibEmWDUj2Q3EbJZdVjaXevb2DUtOuolD9utVlo5duYX%2FuAvElMkRRDct3nDM21A0QebtlLIMCKwuUiMgzES%2F9KBx4wS0J09FRdUNAQoJzn315rBagqjPZSPl4JR16s5uYY%2BA0BU9kdatzDRPejxeDqFgtX%2BjGj%2FepENAJXQlrolu%2B0Vi%2FDg9MEco%2BQczKBvEDp4ovnsfLok%2BBoNDFweK2DbGLkw7%2Bh8I%2BWdo%2Fh
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.