GIFTEDCROOK’s Strategic Pivot: From Browser Stealer to Data Exfiltration Platform During Critical Ukraine Negotiations
ID: 0d898b0f-ec21-5112-9519-dd3951a08754
STIX ID: report--0d898b0f-ec21-5112-9519-dd3951a08754
Feed Name: Arctic Wolf
Arctic Wolf Labs reports that the UAC-0226-linked infostealer GIFTEDCROOK evolved from a browser credential stealer into a multi-version intelligence collection tool (v1 → v1.2 → v1.3) deployed via spear-phishing PDFs and weaponized OLE/macros to exfiltrate browser secrets and sensitive documents from Ukrainian governmental and military targets, using Telegram bots and shared email infrastructure; the report includes technical IOCs, file hashes, YARA rules, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
