SHADOWSNIFF
SHADOWSNIFF is an information-stealing malware/credential stealer described by CERT-UA as a GitHub-hosted stealer. Public reporting places it in phishing campaigns targeting Ukrainian government institutions and other Ukrainian-speaking organizations during January-February 2026, tracked as UAC-0252. In these campaigns, emails impersonated Ukrainian central executive bodies and regional administrations and urged recipients to update widely used civilian and military mobile applications. Delivery methods included attached archives containing executables, links to legitimate but XSS-vulnerable websites that executed JavaScript and downloaded an executable, and exploitation of the WinRAR vulnerability CVE-2025-8088. SHADOWSNIFF was deployed alongside SALATSTEALER, and CERT-UA also reported DEAFTICK in the same activity cluster. The activity has been associated by CERT-UA with individuals discussed on the Telegram channel “PalachPro.” Reported SHADOWSNIFF file indicators include updateV3.23.exe with MD5 2591d145ff510f7fc4d6290d3bfcb130 and SHA-256 3abf295b79992532b03261a81643124d134fa7e86fb901b3bfc74ad0f192dc7f, and another updateV3.23.exe variant with MD5 b6480aa6c364715a21ba28c4d26a5b6e and SHA-256 c2a4212573d7566acf5b610b4ce3598237acd37459670daa1b6950f107d50e03. Related network indicators reported in the same campaign include http://150.241.64.21:8888/client/addclient, http://95.85.224.14:8000/client/addclient, https://nfkavn.bond/client/addclient, and SALATSTEALER-related paths on salat.cn and salator.ru. Host-based behaviors reported for the campaign include hiding %TMP%\svchost.exe, adding a Microsoft Defender exclusion for it, and creating a Run key persistence value WindowsUpdateService pointing to %TMP%\svchost.exe.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SalatStealer was deployed alongside three other tools in a campaign targeting Ukraine, tracked as UAC-0252: SHADOWSNIFF -- secondary credential stealer | UAC-0252 Campaign (Jan--Feb 2026) SalatStealer was deployed alongside three other tools in a campaign targeting Ukraine, tracked as UAC-0252 ... Initial vector: CVE-2025-8088 (WinRAR path traversal) distributed via the PalachPro Telegram channel.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SalatStealer was deployed alongside three other tools in a campaign targeting Ukraine, tracked as UAC-0252: SHADOWSNIFF -- secondary credential stealer
Techniques & procedures
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
4 techniques“...a link to a legitimate website that is vulnerable to XSS (Cross-site scripting), which, when visited, will execute JavaScript code and download the executable file…”
CERT-UA has warned of a hacking campaign targeting Ukrainian government institutions using phishing emails containing a ZIP archive (or a link to a website vulnerable to cross-site scripting attacks) to distribute SHADOWSNIFF and SALATSTEALER...
...phishing emails containing a ZIP archive... to distribute SHADOWSNIFF and SALATSTEALER...
...phishing emails containing a ZIP archive (or a link to a website vulnerable to cross-site scripting attacks)...
Execution
1 techniqueBeget LLC infrastructure hosted activity tied to the UAC-0252 campaign, which impersonated Ukrainian government institutions and deployed SHADOWSNIFF and SALATSTEALER infostealers through a WinRAR vulnerability tracked as CVE-2025-8088.
Stealth
1 techniqueBeget LLC infrastructure hosted activity tied to the UAC-0252 campaign, which impersonated Ukrainian government institutions and deployed SHADOWSNIFF and SALATSTEALER infostealers.
Command and Control
3 techniquesOver a three-month window from January 1 to April 1, 2026, more than 1,250 active command-and-control (C2) servers were detected across 165 Russian infrastructure providers.
hXXp://150[.]241.64.21:8888/client/addclient; hXXps://nfkavn[.]bond/client/addclient; hXXps://salat[.]cn/sa1at/ ...
“The EXE files and scripts are hosted on the legitimate GitHub service.”
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer deployed in the UAC-0252 campaign impersonating Ukrainian government institutions and exploiting a WinRAR vulnerability.
A secondary credential stealer used alongside SalatStealer in the UAC-0252 campaign targeting Ukraine.
A stealer (noted as sourced from GitHub) used in the referenced CERT-UA activity.
Named malware/tool referenced in the report references alongside SalatStealer and UAC-0252.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.