Researchers reported that UAC-0226 deployed the GIFTEDCROOK stealer through weaponized WinRAR archives that abused Alternate Data Streams (ADS) and path traversal to hide malicious content and place a .lnk file in the Windows Startup folder. The shortcut launched an obfuscated PowerShell loader, waited briefly, decoded a staged payload stored in C:\ProgramData, and reflectively mapped a headerless PE image into memory using native Windows APIs, giving the malware persistence while reducing file-based detection. The lure document was themed around Ukrainian reconnaissance and UAV personnel, indicating targeting aligned with Ukrainian military-related users.
Once loaded, GIFTEDCROOK harvested data from Chromium browsers, Firefox, documents, archives, VPN profiles, KeePass databases, Java KeyStores, email files, cookies, credentials, and session data before staging and compressing the stolen information for exfiltration. Researchers said the updated chain expands earlier UAC-0226 tradecraft with automatic Startup persistence, hidden archive content, a custom PE format, reflective DLL loading, and execution telemetry sent to attacker-controlled infrastructure including 142.111.194[.]73:8640, while retaining PowerShell-based obfuscation and in-memory execution techniques.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Synaptic Security analyzed a June 2026 campaign attributed to UAC-0226 that delivered GIFTEDCROOK via a weaponized WinRAR archive abusing ADS-based path traversal. The chain used a malicious Startup-folder LNK, obfuscated PowerShell, and reflective loading to deploy an in-memory stealer targeting Ukrainian military-themed recipients.
On 2026-06-24, Synaptic Security published a reverse-engineering analysis describing the updated UAC-0226/GIFTEDCROOK infection chain, including Startup persistence, additive decoding of wt1, reflective DLL mapping, and telemetry to attacker infrastructure. The report assessed the tooling as an evolution of earlier UAC-0226 activity rather than a distinct malware family.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblog.synapticsystems.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.