UAC-0226 is a Russia-aligned cyber-espionage cluster active against Ukrainian organizations since at least February 2025. It is also tracked as SHADOW-EARTH-066. The group has targeted Ukrainian military innovation organizations, armed-forces units, defense-sector entities, law-enforcement agencies, and regional and state government bodies, with activity particularly affecting organizations near Ukraine’s eastern border. UAC-0226 primarily uses spearphishing attachments for initial access. Early operations used macro-enabled Excel lures that decoded embedded payloads and executed them, while later campaigns used weaponized WinRAR archives exploiting CVE-2025-8088-style path traversal and Alternate Data Stream abuse. These archives use Ukrainian military and reconnaissance-themed decoys while installing hidden payloads and a Startup-folder shortcut for execution at subsequent user logon. The cluster deploys GIFTEDCROOK, a C/C++ information stealer, alongside observed PowerShell-based reverse-shell tooling. GIFTEDCROOK collects saved credentials, cookies, browsing data, and session material from Chromium-based browsers and Firefox; it also searches for documents, archives, email data, VPN profiles, KeePass databases, Java KeyStores, and other sensitive files. Collected material is compressed and exfiltrated. Earlier activity used Telegram for exfiltration, whereas later operations used dedicated command-and-control infrastructure. Recent GIFTEDCROOK delivery chains use heavily obfuscated PowerShell loaders, additive payload encoding, native Windows API-based in-memory execution, and a custom headerless PE format. A reflective loader reconstructs the final DLL in memory, resolves imports and relocations, and starts the stealer while reducing file-based detection opportunities. UAC-0226 also employs artifact cleanup following data theft to hinder forensic investigation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducts targeted credential and document theft against Ukrainian organizations. It shifted from Excel macro droppers to malicious RAR archives exploiting CVE-2025-8088, executes GIFTEDCROOK through a Startup-folder LNK and in-memory PowerShell loader, exfiltrates data to dedicated C2 servers, and deletes artifacts after collection.
Conducting a credential and document theft campaign using booby-trapped WinRAR archives, Alternate Data Streams, obfuscated PowerShell, and reflective PE loading to deliver the GIFTEDCROOK stealer against Ukrainian military-related targets.
Conducting credential and information theft campaigns using weaponized WinRAR archives, LNK-based execution, obfuscated PowerShell loaders, additive payload encoding, reflective in-memory loading, and browser/document/VPN/KeePass theft against Ukrainian military-themed targets.
Conducting stealer campaigns using weaponized WinRAR archives with Ukrainian military-themed decoys, LNK-based execution, obfuscated PowerShell loaders, additive payload encoding, reflective in-memory loading, persistence via Startup folder placement, and theft of browser data, documents, VPN configs, KeePass databases, and other sensitive files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.