New GIFTEDCROOK Chain Abuses WinRAR ADS and Reflective Loading to Steal Browser Data
ID: f179468a-4ea7-5bfc-92f3-66f0154b4b26
STIX ID: report--f179468a-4ea7-5bfc-92f3-66f0154b4b26
Feed Name: cybersecurityNews.com
Threat Score
**Targeted GIFTEDCROOK campaign:** Researchers attribute a sophisticated campaign by UAC-0226 that uses WinRAR Alternate Data Streams, LNK decoys, heavily obfuscated PowerShell, and reflective PE loading to deploy the GIFTEDCROOK infostealer against Ukrainian military-related personnel, exfiltrating browser credentials, cookies, VPN/KeePass/email data to a tracked C2 endpoint while providing multiple file, hash, path, and network IoCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
