GIFTEDCROOK
- Malware type
- credential-stealer
- Profile updated
- 2026-07-07 13:16:07
Targeted industries: government-and-public-sector
Context
According to CERT-UA, this stealer used by UAC-0226 is written in C/C++, targeting browser databases and using telegram for data exfiltration.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Giftedcrook_Auto (yara-rule)
Reports & references
- CERT-UA — 6282946 (report)
- socprime.com — Detect Uac 0226 Attacks Against Ukraine (report)
- cip.gov.ua — Novi Kiberzagrozi Kogo I Yak Atakuyut Vorozhi Ugrupovannya (report)
- securityaffairs.com — Ukraine Sees Surge In Ai Powered Cyberattacks By Russia Linked Threat Actors (report)
- cip.gov.ua — Download (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Giftedcrook (report)
- arcticwolf.com — Giftedcrook Strategic Pivot From Browser Stealer To Data Exfiltration Platform (report)