Wire Observer.
Technology

Steganographic PNGs and Rogue Notepad++ Plugins Reveal New Espionage Campaign Targeting Ukrainian Entities

Steganographic PNGs and Rogue Notepad++ Plugins Reveal New Espionage Campaign Targeting Ukrainian Entities

A cyber‑espionage operation linked to the Russia‑aligned group Earth Sirrush has been uncovered distributing malicious code through seemingly innocuous PNG images and compromised Notepad++ plug‑ins. The campaign, active since at least 2022, is aimed at a range of Ukrainian institutions, including ministries, defense bodies, border‑guard units and logistics firms.

Analysts say the attackers embed payloads inside PNG files using steganographic techniques that hide the malicious binaries from casual inspection. When a victim opens the image with a specially crafted viewer, the concealed code is extracted and executed, granting the adversary a foothold on the system.

In parallel, the threat actors have weaponised Notepad++ – a popular open‑source text editor – by publishing tampered plug‑ins on third‑party repositories. Users who install these extensions inadvertently introduce a backdoor that communicates with command‑and‑control servers, allowing the group to exfiltrate data and move laterally within networks.

Security researchers from multiple firms traced the infrastructure to servers located in Russia and noted reuse of code signatures from earlier Earth Sirrush operations. The choice of PNG steganography and a trusted development tool reflects a broader trend of leveraging everyday file formats and software to bypass traditional security controls.

Ukrainian officials have been alerted, and cybersecurity teams are urged to verify the integrity of image files and to restrict the installation of Notepad++ extensions to verified sources. Ongoing monitoring and threat‑intelligence sharing are expected to play a crucial role in mitigating further compromise as the campaign evolves.

Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related