UAC-0226
UAC-0226 is a Russian espionage threat cluster tracked by CERT-UA and SSSCIP, with activity monitored since at least February 2025. The group has conducted cyber-espionage operations against Ukraine, primarily targeting military innovation hubs, armed forces units, defense industrial innovation organizations, law enforcement entities, and regional/state and local government bodies, including organizations near Ukraine’s eastern border. Reported targeting also includes defense, government, and law enforcement sectors more broadly. The cluster is associated with phishing campaigns delivering the GIFTEDCROOK stealer and a reverse-shell payload. Initial access has been observed via malicious email attachments, especially macro-enabled Excel (.xlsm) files using lures such as landmine clearance, administrative fines, drone production, and compensation for damaged property. CERT-UA reported that the malicious spreadsheets contained base64-encoded payloads hidden in cells; embedded macros decoded the payloads, wrote executables without file extensions, and executed them on victim systems. Phishing emails were reportedly sent from compromised accounts, including via webmail. UAC-0226 is linked to GIFTEDCROOK, described as a C/C++ infostealer. GIFTEDCROOK extracts browser data from Chrome, Microsoft Edge, and Mozilla Firefox, including cookies, browsing history, and saved credentials. The malware archives collected data using PowerShell Compress-Archive and exfiltrates it via Telegram to attacker-controlled chats. Reporting also notes a related .NET-based tool embedding a PowerShell reverse shell script sourced from the public GitHub repository PSSW100AVB. Known alias in the provided content: UAC-0226.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- defense
- government
- law-enforcement
Tradecraft
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UAC-0226 targets Ukrainian defense, government, and law enforcement with malware-laden email attachments, using GIFTEDCROOK to steal browser data and exfiltrate it via Telegram.
Phishing-driven distribution of the GIFTEDCROOK stealer targeting Ukrainian defense-innovation organizations and public-sector/security entities.
Russian espionage activity against Ukraine using the GIFTEDCROOK infostealer/data-exfiltration tooling.
Cyber-espionage campaign against Ukraine (military innovation hubs, armed forces, law enforcement, and regional/local government bodies near the eastern border) using phishing with macro-enabled Excel lures to deploy a .NET tool (PowerShell reverse shell) and the GIFTEDCROOK C/C++ stealer; data is archived and exfiltrated via Telegram.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.