Earth Sirrush Employs PNG Steganography and Malicious Notepad++ Plugins for Espionage Against Ukraine
The Russia-aligned threat actor Earth Sirrush (UAC-0099) is escalating its espionage campaigns against Ukrainian organizations by hiding malware within PNG images and malicious Notepad++ plugins.

The Russia-aligned threat actor known as Earth Sirrush, also tracked as UAC-0099, has intensified its espionage operations targeting Ukrainian government agencies, defense organizations, border guards, and logistics operators. Since at least 2022, the group has consistently evolved its toolset to maintain persistent access within Ukraine's critical wartime supply networks. Recent campaigns demonstrate a sophisticated approach, beginning with highly tailored phishing messages, malicious archives, and documents designed to impersonate trusted institutions.
Earlier operations by Earth Sirrush exploited known vulnerabilities, such as CVE-2023-38831 in WinRAR. However, newer campaigns showcase a blend of convincing download pages and cleverly concealed payloads. Researchers from TrendAI have identified a continuous thread connecting these activities from 2022 through July 2026, noting that the group has developed over ten distinct malware families while retaining recognizable development patterns and infrastructure. Previously identified as SHADOW-EARTH-065, Earth Sirrush's persistent evolution aligns with CERT-UA's UAC-0099 designation, indicating a sustained focus on intelligence gathering rather than opportunistic theft.
In 2026, Earth Sirrush significantly expanded its use of steganography, a technique for hiding data within seemingly innocuous files. One notable campaign, dubbed CINDERBLOT or BadPaw, utilized phishing emails impersonating Ukraine's State Border Guard Service to initiate the infection chain. Another operation mimicked a drone parts company, directing victims to a professional-looking website where a fraudulent antivirus verification message prompted the download of weaponized ZIP archives, effectively leveraging familiar commercial branding to build trust.
The attackers are adept at concealing their malicious payloads within PNG image files, often using scheduled tasks to execute them. While PNG steganography is not new, Earth Sirrush employs multiple methods, including appending code directly after image data and extracting hidden content from pixel data using PowerShell scripts. In July 2026, CERT-UA documented a separate attack chain initiated by LUNCHPOKE, a malicious plugin for the Notepad++ code editor. This plugin uses DLL proxying to execute attacker-controlled code when the editor launches, making the abuse of legitimate software a viable delivery vector.
LUNCHPOKE serves as a dropper for BURNYBEAR, a .NET loader, and its updated variant, MATCHBOIL.V2, which features enhanced encryption and improved concealment techniques. These components are deployed in randomized, writable directories, and renamed Windows scheduling utilities are used to ensure frequent execution. Concurrently, a parallel infection chain utilizes Windows startup settings for persistence, demonstrating the group's adaptability in maintaining access.
Among the newer tools in Earth Sirrush's arsenal is ASHVEIN, a previously undocumented .NET information stealer and remote access trojan. ASHVEIN is capable of stealing credentials from popular browsers like Chrome and Firefox, capturing screenshots, exfiltrating files, executing remote PowerShell commands, and gathering system information. It encrypts its communications, actively checks for common malware analysis tools, and employs techniques like hiding instructions within invisible webpage elements. Some variants also use GitHub as a fallback for command and control server information, providing redundancy.
Researchers have connected these evolving malware families through shared encryption code, identical system identification queries, reused signature artifacts, recurring development traces, and infrastructure relationships. Many command servers utilized the same registrar and Cloudflare fronting, with backend systems concentrated within a single hosting network. The group's ability to maintain implants for extended periods, even without server communication, highlights their focus on long-term intelligence gathering.
Defenders are advised to block confirmed malicious infrastructure and monitor for suspicious activities such as unusual plugin loading, renamed scheduling utilities, executable creation in writable directories, and executable code appended to image files. Enhanced PowerShell logging, auditing access to protected credentials, and monitoring unusual browser data access are also recommended. Security awareness training for staff, focusing on recognizing institutional impersonation and verifying document signatures, remains crucial, particularly for organizations in the government, defense, border security, and logistics sectors.