Earth Sirrush Uses PNG Steganography and Malicious Notepad++ Plugins to Deploy Espionage Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Earth Sirrush is hiding espionage malware inside PNG images and malicious Notepad++ plugins to compromise Ukrainian organizations.

The Russia-aligned group has targeted government agencies, defense organizations, border guards, and logistics operators since at least 2022, repeatedly changing its tools to maintain access across the country’s wartime supply networks.

The attacks begin with carefully tailored phishing messages, malicious archives, and documents impersonating trusted institutions.

Earlier campaigns also exploited the WinRAR vulnerability CVE-2023-38831, while newer operations combine convincing download pages with concealed payloads and software components that appear legitimate.

Researchers from TrendAI identified links across these campaigns, tracing the activity from 2022 through July 2026.

TrendAI said in a report shared with Cyber Security News (CSN) that the group developed more than 10 malware families while retaining recognizable development and infrastructure patterns.

Previously tracked as SHADOW-EARTH-065, Earth Sirrush overlaps with CERT-UA’s UAC-0099 designation. Its history of evolving UAC-0099 attack methods provides context for the latest findings, which point to sustained intelligence gathering rather than quick theft followed by an immediate departure.

Earth Sirrush Uses PNG Steganography and Malicious Notepad++ Plugins

In 2026, the group expanded its use of steganography, a technique that hides information inside ordinary files. One campaign, tracked as CINDERBLOT and also known as BadPaw, used phishing messages impersonating Ukraine’s State Border Guard Service to draw recipients into the infection chain.

A later operation impersonated a drone parts company and directed victims to a professional-looking website. A fraudulent antivirus verification message encouraged downloads of weaponized ZIP archives, illustrating how familiar commercial branding can make a malicious delivery page appear trustworthy to prospective buyers.

Earth Sirrush Uses PNG Steganography and Malicious Notepad++ Plugins
Earth Sirrush Uses PNG Steganography and Malicious Notepad++ Plugins

The attackers concealed payloads inside PNG images and used scheduled tasks to launch them. Similar PNG malware concealment techniques have appeared in other campaigns, but Earth Sirrush used multiple approaches, including appending code after image data and extracting hidden content from pixels with PowerShell.

In July 2026, CERT-UA documented another chain beginning with LUNCHPOKE, a malicious Notepad++ plugin. Through DLL proxying, the plugin runs attacker code when the editor starts, making abuse of Notepad++ plugins a delivery route that relies on familiar software rather than an obviously suspicious application.

LUNCHPOKE deploys BURNYBEAR, a .NET loader, and MATCHBOIL.V2, an updated loader with stronger encryption and revised concealment.

Components reside in randomized, writable directories, while renamed Windows scheduling utilities establish frequent execution; a parallel image-based chain uses Windows startup settings to preserve access.

Espionage and Defenses

Among the group’s newer tools is ASHVEIN, a previously undocumented .NET information stealer and remote access trojan.

Its capabilities include stealing Chrome and Firefox credentials, capturing screenshots, retrieving files, running remote PowerShell commands, and collecting identifying information about the compromised computer.

ASHVEIN encrypts communications and checks for tools commonly used to investigate malware. It also hides instructions inside invisible webpage elements, while some variants use GitHub as a fallback source for server information, providing alternative ways to reconnect when the primary route is unavailable.

Earth Sirrush C&C infrastructure (Source - TrendAI)
Earth Sirrush C&C infrastructure (Source – TrendAI)

The findings extend earlier reporting on UAC-0099 loader delivery chains across Ukrainian targets. Researchers connected changing malware families through shared encryption code, identical system-identification queries, reused signature artifacts, recurring development traces, and infrastructure relationships, rather than treating any single clue as decisive evidence.

Many confirmed command servers used the same registrar and Cloudflare fronting, with backend systems concentrated in one hosting network.

In one observed case, scheduled-task persistence preserved an implant through a month without server communication, underscoring the group’s ability to maintain long-term footholds.

TrendAI recommends blocking confirmed malicious infrastructure while treating shared backend systems as supporting evidence, not proof by themselves.

Defenders should investigate unusual plugin loading, renamed scheduling utilities, executable creation in writable directories, suspicious virtual disk mounts, and executable code appended to image files.

The report also recommends PowerShell logging and restrictions, auditing access to protected credentials, and monitoring unusual browser-data access.

Staff should learn to recognize targeted institutional impersonation, verify incoming document signatures, and watch for concealed file extensions, particularly across government, defense, border security, and logistics organizations, where convincing correspondence can conceal a persistent compromise.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain order.cyberflysystems[.]com Fraudulent drone-parts download page displaying a fake antivirus verification badge.
File name KittyCat.png PNG file identified as containing a concealed malware payload.
File name schtasks.exe Legitimate Windows scheduling utility abused through renamed copies. Its presence alone does not establish compromise.
Directory C:UsersPublicLibraries Shared staging location associated with the campaigns; executable creation here warrants investigation.
File extension .library-ms Windows library-description files repeatedly used across associated operations. Not inherently malicious.
File name Local State Chrome file that defenders should monitor for unusual access associated with credential theft. Not itself malicious.
Component name AnswerFromPolice Delivery component displaying a document impersonating the National Police of Ukraine while deploying malware.
Malware identifier TelemetryBrowser Developer-assigned name for the malware tracked as ASHVEIN.
Metadata artifact TelemetryUP Branding shared between ASHVEIN metadata and related infrastructure.
Infrastructure context Regery.com Legitimate registrar used for many confirmed command-and-control domains; not an attacker-controlled domain indicator.
Autonomous system AS399629 BL Networks hosting network containing clustered backend systems. Supporting infrastructure context, not a standalone blocking indicator.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Earth Sirrush Uses PNG Steganography and Malicious Notepad++ Plugins to Deploy Espionage Malware appeared first on Cyber Security News.