logo

GIFTEDCROOK’s Strategic Pivot: From Browser Stealer to Data Exfiltration Platform During Critical Ukraine Negotiations

ID: 0d898b0f-ec21-5112-9519-dd3951a08754

STIX ID: report--0d898b0f-ec21-5112-9519-dd3951a08754

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2025-06-26

Date Updated: 2026-07-26

Author: Arctic Wolf Labs

...
...

Arctic Wolf Labs reports that the UAC-0226-linked infostealer GIFTEDCROOK evolved from a browser credential stealer into a multi-version intelligence collection tool (v1 → v1.2 → v1.3) deployed via spear-phishing PDFs and weaponized OLE/macros to exfiltrate browser secrets and sensitive documents from Ukrainian governmental and military targets, using Telegram bots and shared email infrastructure; the report includes technical IOCs, file hashes, YARA rules, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.