GIFTEDCROOK’s Strategic Pivot: From Browser Stealer to Data Exfiltration Platform During Critical Ukraine Negotiations
ID: ef8db9ab-6164-5de6-a738-18a65faa55db
STIX ID: report--ef8db9ab-6164-5de6-a738-18a65faa55db
Feed Name: Arctic Wolf
Arctic Wolf Labs analyzes an active intelligence-gathering campaign by UAC-0226 using the GIFTEDCROOK infostealer (versions v1 through v1.3) that evolved from a browser credential stealer to a document- and secrets-exfiltration tool delivered via spear-phishing PDFs and malicious OLE/macro Excel lures; the malware collects browser data and files (filtered by extension, size, and age), encrypts archives, and exfiltrates to attacker-controlled Telegram bots, with multiple IoCs, YARA rules, and recommended mitigations provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
