Researchers linked a GIFTEDCROOK stealer campaign associated with UAC-0226 to a misconfigured Apache server that exposed thousands of malware staging files. Analysis of the infrastructure uncovered 3,788 files in an open directory, including 947 each of LNK files, VBS scripts, PowerShell scripts, and PDF decoys, indicating an automated distribution pipeline. The infection chain used a compressed archive to deliver a shortcut file that launched a VBS script, displayed a benign refund-form PDF in Microsoft Edge as a decoy, and retrieved a PowerShell payload from refundonex[.]com before beaconing to a tracking API endpoint with a static key.
The PowerShell stage was designed to frustrate analysis by running with execution-policy bypass and reconstructing its final payload at runtime. Embedded AES key and IV values were used to decrypt Base64-encoded chunks into a larger script, which was then executed via Invoke-Expression; separate reporting on the same activity described the operation as a GIFTEDCROOK stealer sample tied to UAC-0226 and highlighted how low-effort obfuscation and exposed hosting infrastructure enabled broad malware distribution while complicating static detection.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
The published analysis described the campaign’s execution flow: a VBS script opened a refund-form PDF decoy in Edge, downloaded a PowerShell payload from refundonex[.]com, executed it with ExecutionPolicy Bypass, and contacted a tracking API endpoint using a static key. It also revealed the PowerShell payload reconstructed encrypted script chunks at runtime with embedded AES keying material and executed them via Invoke-Expression.
Robin Dost published analysis of a stealer campaign after investigating a malicious LNK sample and finding a misconfigured Apache server exposing 3,788 auto-generated files. The archive included 947 each of LNK, VBS, PowerShell, and PDF decoy files, showing a scaled infection chain from RAR to VBS to PS1.
Synaptic Security published research detailing how obfuscation used in a UAC-0226 GIFTEDCROOK stealer sample could be broken down and analyzed. This indicates technical details of the malware’s implementation were publicly revealed by that date.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
blog.synapticsystems.de
Open sourceblog.synapticsystems.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.