Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors uac-0226

Description

A fresh GIFTEDCROOK stealer variant was identified as part of a UAC-0226 campaign targeting Ukraine. Initial access leverages CVE-2025-6218 and CVE-2025-8088 through a weaponized RAR archive containing a decoy PDF themed around military registry information. The attack chain uses an LNK file to execute obfuscated PowerShell code that decodes and deploys the payload. The stealer employs RC4 encryption for data protection, chunks exfiltration into 133KB segments, and uses runtime-reconstructed C2 communication. Despite heavy obfuscation including useless function calls, random variables, and noise, the malware follows a straightforward execution flow: generating seed cookies, dispatching functions, encrypting data with RC4 using the key 'JtyIQxPND8G', and exfiltrating stolen information via HTTP to the command-and-control server. The architecture demonstrates effective simplicity rather than sophisticated complexity.

Goals & Targeting

Targeted Sectors

Government

Targeted Countries / Regions

Ukraine

AI Analysis

· 2 weeks ago

Executive Summary

UAC-0226, a suspected cyber threat actor, has been observed targeting Ukrainian government entities through a campaign employing a GIFTEDCROOK stealer variant. The group's attack chain begins with weaponized RAR archives exploiting CVE-2025-6218 and CVE-2025-8088, followed by the deployment of malware via obfuscated PowerShell code. Despite its simplicity, UAC-0226 demonstrates effective persistence techniques, including RC4 encryption for stolen data and HTTP-based C2 communication.

Goals & Targeting

UAC-0226 appears to target government entities in Ukraine, likely with the goal of cyberespionage or disruption. The choice of targeting suggests a focus on gathering sensitive information or undermining governmental operations. The use of military-themed phishing attempts indicates an effort to compromise individuals within defense or related sectors.

Enhanced Description

UAC-0226 has emerged as a potentially significant threat actor targeting critical infrastructure in Ukraine, leveraging a sophisticated yet streamlined approach to cyber attacks. The group's primary tool appears to be a variant of the GIFTEDCROOK stealer, which is distributed through a weaponized RAR archive containing decoy PDF documents themed around military registry information. This phishing method suggests an attempt to gain victim trust by using a timely and locally relevant topic. Once executed, the payload drops an LNK file that triggers obfuscated PowerShell code to decode and deploy the malware. The GIFTEDCROOK stealer employs RC4 encryption for data protection and exfiltrates stolen information in 133KB chunks to avoid detection. Notably, despite its heavy obfuscation techniques—such as random variable naming and noise generation—the malware maintains a straightforward execution flow focused on data collection and transmission. UAC-0226's operational approach highlights a balance between technical simplicity and effective exploitation methodology.

Key Capabilities

  • Exploitation via CVE-2025-6218 and CVE-2025-8088
  • Weaponized RAR archive creation with decoy PDFs
  • Obfuscated PowerShell execution
  • RC4 encryption for data protection
  • Chunked exfiltration of stolen information
  • HTTP-based C2 communication
  • Spear-phishing campaign targeting government employees

MITRE ATT&CK Tactics

Initial Access
Proling
Obfuscation
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1065.003
T1087
T1055
T1036
T1005
T1048

Software / Tooling

GIFTEDCROOK stealer
RAR archives
LNK files
PowerShell code

Campaigns & Victims

UAC-0226's campaign in Ukraine demonstrates a focused targeting strategy, leveraging known vulnerabilities and psychological manipulation to gain initial access. The group appears to focus on compromising government systems, likely for intelligence gathering or disruptive purposes. Notable for its simplicity in malware architecture compared to more sophisticated actors, UAC-0226 compensates with effective deployment techniques.

IOC Patterns

  • Spear-phishing emails containing RAR archives
  • Obfuscated PowerShell scripts executing via LNK files
  • HTTP traffic to domains associated with C2 servers
  • Registry entries for persistence

Recommended Actions

  • Implement multi-layered network defense, including email filtering and endpoint detection
  • Train users to recognize phishing attempts, especially those targeting government employees
  • Monitor for RAR attachments in emails originating from internal Ukraine-related topics
  • Deploy scripts to detect obfuscated PowerShell activity within the network
  • Conduct regular audits of account access and data integrity
  • Maintain robust backups to mitigate potential ransomware activity

Suggested Tags

Cyberespionage
Government Sector
Geopolitical
Ukraine
APT-like
Malware Campaign

Confidence Assessment

Moderate confidence in the identification of UAC-0226 as a threat actor with specific targeting in Ukraine. The analysis is limited by the absence of historical campaign data and long-term TTP observations, making it difficult to fully characterize the group's objectives or operational scope.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
Government Targeting
Cyberespionage
Government Sector
Geopolitical
Ukraine
APT-like
Malware Campaign

Details

Type
Unknown
Confidence
55%
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.