logo

GIFTEDCROOK’s Strategic Pivot: From Browser Stealer to Data Exfiltration Platform During Critical Ukraine Negotiations

ID: 3ab2ab52-d3d9-5c57-9ecc-f239089f5eb8

STIX ID: report--3ab2ab52-d3d9-5c57-9ecc-f239089f5eb8

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2025-06-26

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs documents GIFTEDCROOK—an evolving infostealer attributed to UAC-0226—detailing its progression from browser credential theft to targeted document and browser-secret exfiltration (v1 → v1.2 → v1.3). The campaign uses spear‑phishing PDFs that link to OLE/macro lures, drops PE implants that collect files (filtered by extension, size, and modification date), encrypts archives, and exfiltrates to Telegram bots; the report includes hashes, Telegram bot tokens, file paths, a YARA rule, and recommended detections and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.