HomeSecurityBeware! GIFTEDCROOK malware has been upgraded!

Attention! GIFTEDCROOK malware has been upgraded!

The attacker behind the GIFTEDCROOK malware has significantly upgraded the tool, turning it from a simple browser data thief into a full-fledged sensitive information collection platform.

GIFTEDCROOK malware

In a recent report by Arctic Wolf Labs, it is stated that new attacks demonstrate GIFTEDCROOK's improved ability to extract a wide range of private documents from targeted devices.

It is believed that this change, combined with the content of the phishing baits, suggests that the attack is focused on gathering information from Ukrainian government and military services.

The malware was first recorded in April 2025 by the Computer Emergency Response Team of Ukraine (CERT-UA), as part of campaigns targeting military agencies, law enforcement agencies, and local authorities.

See also: Beware! Popular TikTok videos promote malware apps

The activity is attributed to the hacking group UAC-0226 and is based on phishing attacks via email, with attached Excel files containing malicious macros, which act as a gateway for the deployment of the GIFTEDCROOK malware.

As an information thief, GIFTEDCROOK aims to steal cookies, browsing history, and authentication data from popular browsers such as Google Chrome, Microsoft Edge, and Mozilla Firefox.

Arctic Wolf's analysis revealed that the malware started as a prototype in February 2025 and was enhanced with versions 1.2 and 1.3, which added the ability to collect documents and files up to 7MB, focusing on files created or modified in the last 45 days.

File types searched include document formats (.doc, .docx, .pdf), presentation formats (.pptx, .ppt), spreadsheet formats (.xls, .xlsx, .csv), image formats (.jpeg, .jpg, .png), compressed files (.rar, .zip), email formats (.eml), and database formats (.sqlite), among others.

The email attacks exploit military themes and include PDF files to lure users into clicking on a Mega cloud storage link, which hosts a malicious Excel file with macros enabled (“Список оповіщених вичеозоб'знахотних организациї 609528.xlsm”). When recipients enable the macros, the GIFTEDCROOK malware is downloaded. Many users do not realize how often Excel files with macros are used in phishing attacks, as such spreadsheets are considered common in business or government emails, and thus easily bypass security defenses.

See also: WinRAR fixes bug that allows malware to launch

The information collected by the GIFTEDCROOK malware is collected in ZIP files and sent in chunks via a Telegram channel controlled by the attacker. If the size exceeds 20 MB, the data is split into multiple parts to avoid detection by traditional network filters. In the final stage, a batch script is executed that deletes traces of the malware from the infected computer.

The threat is not limited to password theft or online behavior monitoring; it is targeted cyberespionage. The recent ability of GIFTEDCROOK to harvest PDFs, spreadsheets, and VPN settings shows that the primary goal is the mass collection of sensitive information. For those working in the public sector or handling confidential documents, this form of theft poses a serious threat not only to the individual but also to entire networks.

As Arctic Wolf reports, the timing of the attacks coincides with important geopolitical events, such as the recent negotiations between Ukraine and Russia in Istanbul. The evolution of the GIFTEDCROOK malware from simple credential theft to more complex document extraction reflects coordinated efforts to tailor the malware to geopolitical objectives, with the aim of enhancing intelligence collection from compromised Ukrainian systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Attention! GIFTEDCROOK malware has been upgraded!

Protection from info-stealer malware

Static detection methods for security are not enough to avoid malware . A more robust approach should incorporate antivirus software , equipped with advanced analysis capabilities.

It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.

See also: Hackers abuse ConnectWise to hide malware

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers.

Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS