Incident
Published 2026-10-05
Verified 2026-10-08

TrendAI: Russia-aligned Earth Sirrush (UAC-0099) has run four years of spear-phishing against Ukrainian government, defence, border guard and logistics targets, now hiding payloads in PNG images and a rogue Notepad++ plugin and adding a new stealer, ASHVEIN

TrendAI Research published a report on 5 October 2026 linking more than four years of espionage campaigns to Earth Sirrush, a Russia-aligned intrusion set previously tracked as SHADOW-EARTH-065 that overlaps with CERT-UA's UAC-0099. Since at least 2022 it has sent tailored spear-phishing to Ukrainian government agencies, defence organisations, border guard units and logistics operators, using malicious archives and documents that impersonate police, border, tax and justice authorities and, more recently, a drone-parts supplier with a convincing download site and a fake antivirus check. Earlier waves exploited the WinRAR flaw CVE-2023-38831. The group has built more than 10 malware families, moving from PowerShell and Go to C# loaders and .NET implants. In 2026 it leaned on steganography, hiding payloads in PNG images either appended after the image data or pulled out of the pixels with PowerShell, including the border-guard-themed CINDERBLOT (also called BadPaw) campaign. In July 2026 CERT-UA documented a chain that starts with LUNCHPOKE, a malicious Notepad++ plugin (NppExport.dll shipped with Notepad++ 8.8.3) that runs through DLL proxying when the editor opens and drops the BURNYBEAR and MATCHBOIL.V2 loaders, kept running by renamed copies of schtasks.exe. The newest tool, ASHVEIN ("TelemetryBrowser" to its developers), is a .NET stealer and remote access trojan that takes Chrome and Firefox credentials, screenshots and files, runs PowerShell, fingerprints the machine, checks for analysis tools, hides tasking in invisible web page elements and can fall back to GitHub to find its server. TrendAI tied the campaigns together through shared encryption code, identical system queries, reused artefacts and infrastructure, with many command servers registered through the same registrar behind Cloudflare. In one case an implant kept its foothold through a month with no server contact. Primary: TrendAI Research; wire: Cyber Security News (7 Oct).

Product
Windows endpoints at Ukrainian government, defence, border and logistics organisations (Notepad++ plugin abuse, WinRAR CVE-2023-38831 in earlier waves)
Versions
n/a — espionage campaign; WinRAR before 6.23 for CVE-2023-38831
Exploited in Australia?
unknown
Patch to
Update WinRAR to 6.23 or later, block archives and virtual-disk files from external mail, and only allow Notepad++ plugins from a managed list (flag NppExport.dll outside the install folder). Alert on renamed copies of schtasks.exe, scheduled tasks firing every few minutes from user-writable folders, and PowerShell that reads pixel data from PNG files.

Primary: TrendAI Research — Earth Sirrush: a Russia-aligned intrusion set with 4 years of evolving espionage tooling (5 Oct 2026) · CVE: CVE-2023-38831 · Cyber Security News — Earth Sirrush uses PNG steganography and malicious Notepad++ plugins to deploy espionage malware (7 Oct 2026)

breaches