A fresh GIFTEDCROOK stealer variant was identified as part of a UAC-0226 campaign targeting Ukraine. Initial access leverages CVE-2025-6218 and CVE-2025-8088 through a weaponized RAR archive containing a decoy PDF themed around military registry information. The attack chain uses an LNK file to execute obfuscated PowerShell code that decodes and deploys the payload. The stealer employs RC4 encryption for data protection, chunks exfiltration into 133KB segments, and uses runtime-reconstructed C2 communication. Despite heavy obfuscation including useless function calls, random variables, and noise, the malware follows a straightforward execution flow: generating seed cookies, dispatching functions, encrypting data with RC4 using the key 'JtyIQxPND8G', and exfiltrating stolen information via HTTP to the command-and-control server. The architecture demonstrates effective simplicity rather than sophisticated complexity.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC-0226, a suspected cyber threat actor, has been observed targeting Ukrainian government entities through a campaign employing a GIFTEDCROOK stealer variant. The group's attack chain begins with weaponized RAR archives exploiting CVE-2025-6218 and CVE-2025-8088, followed by the deployment of malware via obfuscated PowerShell code. Despite its simplicity, UAC-0226 demonstrates effective persistence techniques, including RC4 encryption for stolen data and HTTP-based C2 communication.
Goals & Targeting
UAC-0226 appears to target government entities in Ukraine, likely with the goal of cyberespionage or disruption. The choice of targeting suggests a focus on gathering sensitive information or undermining governmental operations. The use of military-themed phishing attempts indicates an effort to compromise individuals within defense or related sectors.
Enhanced Description
UAC-0226 has emerged as a potentially significant threat actor targeting critical infrastructure in Ukraine, leveraging a sophisticated yet streamlined approach to cyber attacks. The group's primary tool appears to be a variant of the GIFTEDCROOK stealer, which is distributed through a weaponized RAR archive containing decoy PDF documents themed around military registry information. This phishing method suggests an attempt to gain victim trust by using a timely and locally relevant topic. Once executed, the payload drops an LNK file that triggers obfuscated PowerShell code to decode and deploy the malware. The GIFTEDCROOK stealer employs RC4 encryption for data protection and exfiltrates stolen information in 133KB chunks to avoid detection. Notably, despite its heavy obfuscation techniques—such as random variable naming and noise generation—the malware maintains a straightforward execution flow focused on data collection and transmission. UAC-0226's operational approach highlights a balance between technical simplicity and effective exploitation methodology.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC-0226's campaign in Ukraine demonstrates a focused targeting strategy, leveraging known vulnerabilities and psychological manipulation to gain initial access. The group appears to focus on compromising government systems, likely for intelligence gathering or disruptive purposes. Notable for its simplicity in malware architecture compared to more sophisticated actors, UAC-0226 compensates with effective deployment techniques.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the identification of UAC-0226 as a threat actor with specific targeting in Ukraine. The analysis is limited by the absence of historical campaign data and long-term TTP observations, making it difficult to fully characterize the group's objectives or operational scope.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics