New GIFTEDCROOK Malware Targets Ukrainian Government to Steal Sensitive Browser Data

A dangerous new malware named GIFTEDCROOK is targeting Ukrainian government systems. Disguised in phishing emails, this malware is designed to steal sensitive browser data and exfiltrate it through Telegram, making it hard to detect. Cybersecurity experts are warning that this attack is part of a growing trend in cyber-espionage by threat actors.
What is GIFTEDCROOK?
- A newly discovered information-stealing malware focused on browser data—passwords, cookies, and browsing history—mainly from Chrome, Edge, and Firefox.
Who is being targeted?
- Government organizations
- Military innovation centers
- Law enforcement units
- Local agencies near the eastern border
How does the attack begin?
- The malware spreads through phishing emails that contain macro-enabled Excel (.xlsm) files pretending to offer information about landmines, drone production, or property compensation.
Technical Infection Process
- Malicious macros decode and drop payloads
- Payloads include a .NET tool and the GIFTEDCROOK stealer written in C/C++
- Data is compressed using PowerShell
- Data is exfiltrated via Telegram, masking it among regular traffic
Advanced Techniques Used
- Encoded payloads in Excel cells to bypass antivirus
- Use of legitimate GitHub-hosted scripts
- Phishing from compromised accounts to avoid suspicion
- Hidden file extensions and stealthy execution
Larger Pattern of Attacks
- CERT-UA and researchers say this campaign fits into a broader trend, with 44% of 2024 cyber incidents in Ukraine tied to state-sponsored espionage.
The rise of GIFTEDCROOK highlights the growing risk of cyber-espionage targeting critical infrastructure. Organizations, especially government and defense bodies, must train staff to spot phishing, disable macros by default, and monitor PowerShell activity and network traffic for anomalies.
Staying updated and proactive is key in defending against sophisticated threats like GIFTEDCROOK.
- Other (42)
- Ransomware (142)
- Events and News (27)
- Features (45)
- Security (466)
- Tips (79)
- Google (23)
- Achievements (11)
- Products (34)
- Activation (7)
- Dealers (1)
- Bank Phishing (44)
- Malware Alerts (213)
- Cyber Attack (260)
- Data Backup (11)
- Data Breach (98)
- Phishing (156)
- Securty Tips (1)
- Browser Hijack (18)
- Adware (15)
- Email And Password (69)
- Android Security (71)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (71)
- Hacking (57)
- Social Media (8)
- vulnerability (57)
- Hacker (31)
- Spyware (9)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (5)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (7)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (11)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (10)
- Impersonation phishing (1)
- DDoS (5)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)