Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 1 actorExploits 1 CVE

SHADOWSNIFF

SHADOWSNIFF is an information-stealing malware/credential stealer described by CERT-UA as a GitHub-hosted stealer. Public reporting places it in phishing campaigns targeting Ukrainian government institutions and other Ukrainian-speaking organizations during January-February 2026, tracked as UAC-0252. In these campaigns, emails impersonated Ukrainian central executive bodies and regional administrations and urged recipients to update widely used civilian and military mobile applications. Delivery methods included attached archives containing executables, links to legitimate but XSS-vulnerable websites that executed JavaScript and downloaded an executable, and exploitation of the WinRAR vulnerability CVE-2025-8088. SHADOWSNIFF was deployed alongside SALATSTEALER, and CERT-UA also reported DEAFTICK in the same activity cluster. The activity has been associated by CERT-UA with individuals discussed on the Telegram channel “PalachPro.” Reported SHADOWSNIFF file indicators include updateV3.23.exe with MD5 2591d145ff510f7fc4d6290d3bfcb130 and SHA-256 3abf295b79992532b03261a81643124d134fa7e86fb901b3bfc74ad0f192dc7f, and another updateV3.23.exe variant with MD5 b6480aa6c364715a21ba28c4d26a5b6e and SHA-256 c2a4212573d7566acf5b610b4ce3598237acd37459670daa1b6950f107d50e03. Related network indicators reported in the same campaign include http://150.241.64.21:8888/client/addclient, http://95.85.224.14:8000/client/addclient, https://nfkavn.bond/client/addclient, and SALATSTEALER-related paths on salat.cn and salator.ru. Host-based behaviors reported for the campaign include hiding %TMP%\svchost.exe, adding a Microsoft Defender exclusion for it, and creating a Run key persistence value WindowsUpdateService pointing to %TMP%\svchost.exe.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-8088WinRAR for Windows Path Traversal via NTFS Alternate Data StreamsExploited in the wild

SalatStealer was deployed alongside three other tools in a campaign targeting Ukraine, tracked as UAC-0252: SHADOWSNIFF -- secondary credential stealer | UAC-0252 Campaign (Jan--Feb 2026) SalatStealer was deployed alongside three other tools in a campaign targeting Ukraine, tracked as UAC-0252 ... Initial vector: CVE-2025-8088 (WinRAR path traversal) distributed via the PalachPro Telegram channel.

via breakglass intelintel.breakglass.tech
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAC-0252

SalatStealer was deployed alongside three other tools in a campaign targeting Ukraine, tracked as UAC-0252: SHADOWSNIFF -- secondary credential stealer

via breakglass intelintel.breakglass.tech
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

4 techniques
T1189Drive-by CompromiseEvidence1

“...a link to a legitimate website that is vulnerable to XSS (Cross-site scripting), which, when visited, will execute JavaScript code and download the executable file…”

T1566PhishingEvidence2

CERT-UA has warned of a hacking campaign targeting Ukrainian government institutions using phishing emails containing a ZIP archive (or a link to a website vulnerable to cross-site scripting attacks) to distribute SHADOWSNIFF and SALATSTEALER...

T1566.001Spearphishing AttachmentEvidence2

...phishing emails containing a ZIP archive... to distribute SHADOWSNIFF and SALATSTEALER...

T1566.002Spearphishing LinkEvidence2

...phishing emails containing a ZIP archive (or a link to a website vulnerable to cross-site scripting attacks)...

Execution

1 technique
T1203Exploitation for Client ExecutionEvidence3
TacticExecution

Beget LLC infrastructure hosted activity tied to the UAC-0252 campaign, which impersonated Ukrainian government institutions and deployed SHADOWSNIFF and SALATSTEALER infostealers through a WinRAR vulnerability tracked as CVE-2025-8088.

Stealth

1 technique
T1036MasqueradingEvidence1
TacticStealth

Beget LLC infrastructure hosted activity tied to the UAC-0252 campaign, which impersonated Ukrainian government institutions and deployed SHADOWSNIFF and SALATSTEALER infostealers.

T1071Application Layer ProtocolEvidence1

Over a three-month window from January 1 to April 1, 2026, more than 1,250 active command-and-control (C2) servers were detected across 165 Russian infrastructure providers.

T1071.001Web ProtocolsEvidence1

hXXp://150[.]241.64.21:8888/client/addclient; hXXps://nfkavn[.]bond/client/addclient; hXXps://salat[.]cn/sa1at/ ...

T1105Ingress Tool TransferEvidence2

“The EXE files and scripts are hosted on the legitimate GitHub service.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.