Earth Sirrush is a Russia-aligned cyberespionage intrusion set active since at least 2022. Previously tracked as SHADOW-EARTH-065, it overlaps with CERT-UA’s UAC-0099 designation. It targets Ukrainian government agencies, defense organizations, border guard units, and transport and logistics operators, including organizations supporting wartime supply networks. Its operations emphasize intelligence collection and persistent access. The group uses tailored spear-phishing, institutional impersonation, decoy documents, malicious archives, and fraudulent download pages. Lures impersonate Ukrainian police, border security, tax and justice authorities, and drone-parts suppliers. Earlier campaigns exploited the WinRAR vulnerability CVE-2023-38831. Its delivery techniques include DLL sideloading, virtual disk containers, and PNG-based payload concealment, using both appended data and pixel-embedded content extracted with PowerShell. The 2026 CINDERBLOT campaign, also known as BadPaw, employed border-guard-themed phishing. A separate infection chain uses LUNCHPOKE, a malicious Notepad++ plugin that executes through DLL proxying and deploys the BURNYBEAR and MATCHBOIL.V2 loaders. Persistence mechanisms include scheduled tasks and Windows startup registry entries, with renamed legitimate scheduling utilities used to sustain execution. Earth Sirrush’s tooling has evolved from PowerShell and Go components to compiled C# loaders and .NET implants. Its ASHVEIN malware, also named TelemetryBrowser by its developers, combines information-stealing and remote-access capabilities: browser credential theft, screenshot capture, file enumeration and retrieval, remote PowerShell execution, and system fingerprinting. Evasion techniques include encrypted communications, analysis-tool detection, obfuscation, and tasking concealed in invisible webpage elements. Some ASHVEIN variants use GitHub-based fallback server discovery. Shared encryption routines, system-identification queries, development artifacts, and infrastructure relationships connect the group’s evolving malware families and campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-aligned espionage group targeting Ukrainian government, defense, border-security, and logistics organizations since at least 2022. Campaigns documented through July 2026 use evolving malware, concealed payloads, and persistent access to gather intelligence across wartime supply networks. The article describes UAC-0099 as an overlapping designation, rather than establishing exact equivalence. CINDERBLOT, also called BadPaw, is identified as a campaign, not a distinct actor or subgroup.
Russia-aligned espionage group conducting sustained operations against Ukrainian organizations since at least 2022. Its evolving delivery chains use targeted phishing, institutional impersonation, malicious archives, PNG steganography, and malicious Notepad++ plugins. The group deploys loaders and information-stealing remote access malware, maintaining persistent access for intelligence collection. Previously tracked as SHADOW-EARTH-065, its activity overlaps with CERT-UA's UAC-0099 designation; the content does not establish exact equivalence between those clusters.
Russia-aligned intrusion set conducting sustained cyberespionage against Ukrainian government, defense, border-security, transport, and logistics organizations from at least 2022 through July 2026. It repeatedly replaces its malware while retaining recognizable development artifacts, delivery patterns, and infrastructure. Operations emphasize credential theft, surveillance, remote access, and persistent intelligence collection. The report describes overlap with UAC-0099; a possible initial-access relationship with Sandworm remains an assessment rather than an established fact.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.