Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GIFTEDCROOK Malware Exploits WinRAR to Steal Data

GIFTEDCROOK Malware Exploits WinRAR to Steal Data

Posted on June 26, 2026 By CWS

A new cybersecurity threat associated with the group UAC-0226 has been identified, targeting Windows users with sophisticated techniques. The campaign employs malicious WinRAR archives and advanced memory-loading methods to deploy the GIFTEDCROOK malware, which is designed to clandestinely siphon off browser credentials, cookies, and sensitive files from compromised systems.

Targeted Attack on Ukrainian Military Personnel

The attack chain has a specific focus on individuals related to the Ukrainian military, utilizing documents that mimic authentic military records to deceive targets. The infection commences with what seems to be a standard WinRAR archive; however, it contains more than just a simple document.

Utilizing the Alternate Data Streams (ADS) feature, threat actors hide numerous files within the archive, including a decoy PDF and a shortcut file (LNK). These files are discreetly deployed into critical system locations upon opening, initiating the attack without the user’s awareness.

Technical Analysis of the GIFTEDCROOK Attack Chain

Researchers at Synaptic Security have meticulously traced the complete attack sequence while monitoring UAC-0226’s activities. The initial RAR file leads to a decoy PDF, a shortcut, and obfuscated PowerShell scripts, culminating in the execution of the GIFTEDCROOK stealer.

The archive deposits two primary files: an obfuscated PowerShell loader in C:ProgramDataWC3 and an encoded payload in C:ProgramDatawt1. A shortcut in the Windows Startup folder ensures the malware’s persistence, allowing it to launch automatically with each login, thus maintaining continuous access.

Once active, GIFTEDCROOK targets browsers such as Chrome, Edge, Opera, and Firefox, extracting login details, cookies, and session data. Additionally, it seeks VPN profiles, KeePass databases, and email files, consolidating everything into a ZIP archive for transmission to the attackers’ servers.

Evading Detection with Advanced Techniques

The attack leverages WinRAR’s ADS and reflective PE loading capabilities to deliver GIFTEDCROOK while evading detection by most security tools. ADS enables the attachment of hidden files to the archive, which are extracted without raising suspicion.

The PowerShell loader is obfuscated with extraneous code, making it challenging for analysis tools to decipher. The payload is decoded and loaded directly into memory using Windows API calls, bypassing the creation of recognizable executable files on disk.

Security measures should focus on monitoring changes to the startup folder, unusual PowerShell activity, and outbound traffic to atypical ports. Preventing LNK execution from archives and enforcing stricter PowerShell policies can significantly mitigate this threat.

Security teams are advised to stay vigilant and implement robust monitoring to detect signs of this attack chain. By understanding the intricacies of the GIFTEDCROOK malware, organizations can better protect their systems against such sophisticated threats.

Cyber Security News Tags:attack chain, browser credentials, browser data, Cybersecurity, data theft, GIFTEDCROOK, Malware, PowerShell, reflective loading, Security, sensitive information, UAC-0226, Ukrainian military, WinRAR, WinRAR ADS

Post navigation

Previous Post: AI and Cybersecurity Updates: Major Breaches and Layoffs
Next Post: CISA Identifies Critical RCE Vulnerability in PTC Software

Related Posts

Critical FFmpeg Vulnerabilities Allow Remote Code Execution Critical FFmpeg Vulnerabilities Allow Remote Code Execution Cyber Security News
Windows 11 PCs Fail to Shut Down After January Security Update Windows 11 PCs Fail to Shut Down After January Security Update Cyber Security News
UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware Cyber Security News
Cloudflare Fixes Critical Pingora Vulnerabilities Cloudflare Fixes Critical Pingora Vulnerabilities Cyber Security News
New MacSync Stealer Malware Attacking macOS Users Using Digitally Signed Apps New MacSync Stealer Malware Attacking macOS Users Using Digitally Signed Apps Cyber Security News
NANOREMOTE Malware Leverages  Google Drive API for Command-and-Control (C2) to Attack Windows Systems NANOREMOTE Malware Leverages  Google Drive API for Command-and-Control (C2) to Attack Windows Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks
  • Klue Data Breach Expands Amidst Hacker Dispute
  • Guardian Agents: Enhancing Identity Governance for AI
  • Japan’s Army Faces Malware Breach via Infected USB Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks
  • Klue Data Breach Expands Amidst Hacker Dispute
  • Guardian Agents: Enhancing Identity Governance for AI
  • Japan’s Army Faces Malware Breach via Infected USB Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark