GIFTEDCROOK is a Windows information stealer associated with the Russia-aligned UAC-0226 cluster, also tracked as SHADOW-EARTH-066. Active since at least early 2025, it has targeted Ukrainian military, defense-innovation, law-enforcement, and government organizations, particularly through Ukrainian-themed social-engineering lures. Early operations used phishing emails carrying macro-enabled Excel attachments; later campaigns used spear-phishing with weaponized WinRAR archives exploiting CVE-2025-8088 to establish execution at user logon and load the payload in memory.
The malware extracts saved credentials, cookies, browsing data, session material, and cryptographic browser data from Chromium-based browsers and Firefox. Updated variants can recover DPAPI-protected Chromium secrets and bypass Chrome App-Bound Encryption, including by injecting code into suspended Chromium browser processes operating in the appropriate security context. GIFTEDCROOK also searches for and stages sensitive files, including documents, archives, email data, VPN configurations, KeePass databases, and Java KeyStores.
Modern variants use obfuscated PowerShell loaders, native Windows memory-management APIs, direct system-call techniques, and custom reflective PE loading to reduce reliance on a conventional executable on disk and evade user-mode monitoring. Collected data is compressed, RC4-encrypted, and exfiltrated over HTTPS to dedicated command-and-control infrastructure. Earlier variants used Telegram for exfiltration. The malware has employed Startup-folder persistence and can remove staging artifacts and persistence after data theft to reduce forensic evidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Gamaredon and UAC-0226 are actively exploiting CVE-2025-8088, a CVSS 8.8 WinRAR path traversal flaw, to place malicious payloads outside the intended RAR extraction directory, including in the Windows Startup folder. | The PowerShell loader launches GIFTEDCROOK (result.dll), an updated information stealer targeting saved passwords and cookies from Chromium-based browsers (Chrome, Edge, Opera) and Firefox, as well as documents matching specific extensions from the victim's machine.
I analyzed a UAC-0226 campaign delivering a GIFTEDCROOK stealer through a weaponized WinRAR archive... Underneath that loader sits a browser and file stealer targeting Chromium, Firefox, documents, VPN configurations, KeePass databases and other potentially sensitive material.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The PowerShell loader launches GIFTEDCROOK (result.dll), an updated information stealer targeting saved passwords and cookies from Chromium-based browsers (Chrome, Edge, Opera) and Firefox, as well as documents matching specific extensions from the victim's machine.
This report details a targeted cyber-espionage campaign conducted by the Russia-aligned threat actor group APT SHADOW-EARTH-066 ... delivering an updated variant of the GIFTEDCROOK information stealer against Ukrainian military and government entities.
SHADOW-EARTH-066 / UAC-0226 appears as a separate Russia-aligned campaign exploiting the same WinRAR flaw, using GIFTEDCROOK-family credential and document theft.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The LNK shortcut... spawns a PowerShell loader... GammaSteel deploys 71 DPAPI-encrypted PowerShell modules into the Windows registry.
Click for IIM Chain { ... "name": "Obfuscated/Compressed Files and Information", "tactic": "Defense Evasion", "technique_id": "T1027" ... }
To evade static analysis and conceal its dependencies from traditional import table inspection, the shellcode dynamically resolves required modules like kernel32.dll using API hashing. The hashing algorithm used in this sample is: FNV-1a
The decoded data is copied into the current PowerShell process and executed at a fixed offset.
Once exfiltration is completed, all malicious artifacts are deleted from the host to erase the forensic trail.
Click for IIM Chain { ... "name": "Deobfuscate/Decode Files or Information", "tactic": "Defense Evasion", "technique_id": "T1140" ... }
The payload looks for: Login Data Cookies Network\Cookies ... Firefox ... cookies.sqlite
GIFTEDCROOK... [targets] documents matching specific extensions from the victim's machine. GammaSteel... monitors local drives, network shares, and USB insertions in real time [for] targeted files.
The resulting 16-byte structure is sent to: hxxps://142.111.194[.]73:8640/dj5FZEiLnA/
The malware then initializes a libcurl session and performs an HTTPS POST request with the encrypted packet as the request body.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer delivered via spear-phishing and exploitation of WinRAR CVE-2025-8088. It uses a PowerShell loader and shellcode with direct/indirect syscall techniques and FNV-1a API hashing to evade EDR, establishes persistence via a Startup LNK, steals browser credentials/cookies/session data and local documents, encrypts stolen data with RC4, compresses it into ZIP archives, exfiltrates it over HTTPS to C2 infrastructure, and performs self-cleanup.
An information stealer deployed in memory as result.dll that harvests browser passwords, cookies, and selected documents, exfiltrates them to dedicated C2 servers, then deletes malicious artifacts to limit forensic evidence.
Credential-stealing malware delivered via WinRAR ADS, LNK, and obfuscated PowerShell loaders. It steals browser credentials, cookies, session files, VPN profiles, KeePass databases, and email files, stages the data in a ZIP archive, and exfiltrates it to attacker-controlled infrastructure while maintaining persistence via a startup shortcut.
Browser and file stealer used in UAC-0226 campaigns. It steals data from Chromium-based browsers and Firefox, collects documents and archives, and targets sensitive material including VPN configurations, KeePass databases, Java KeyStores, cookies, and stored credentials. In the June 2026 sample it is delivered via a weaponized WinRAR archive, staged through PowerShell, and loaded as a headerless PE with a custom reflective mapper.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.