Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Obfuscation Without Effort: Breaking a GIFTEDCROOK Stealer

https://136.0.141.138:8406/rcv/

TLP:CLEAR
Active

URL

Description

A fresh GIFTEDCROOK stealer variant was identified as part of a UAC-0226 campaign targeting Ukraine. Initial access leverages CVE-2025-6218 and CVE-2025-8088 through a weaponized RAR archive containing a decoy PDF themed around military registry information. The attack chain uses an LNK file to execute obfuscated PowerShell code that decodes and deploys the payload. The stealer employs RC4 encryption for data protection, chunks exfiltration into 133KB segments, and uses runtime-reconstructed C2 communication. Despite heavy obfuscation including useless function calls, random variables, and noise, the malware follows a straightforward execution flow: generating seed cookies, dispatching functions, encrypting data with RC4 using the key 'JtyIQxPND8G', and exfiltrating stolen information via HTTP to the command-and-control server. The architecture demonstrates effective simplicity rather than sophisticated complexity.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Obfuscation Without Effort: Breaking a GIFTEDCROOK Stealer
Pattern Type
STIX
Confidence
75%
Valid From
May 14, 2026 23:09
Total Sightings
0
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of https://136.0.141.138:8406/rcv/

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.