Skip to main content
Mallory
MalwareUsed by 1 actorExploits 1 CVE

result.dll

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-8088WinRAR Windows Path Traversal via NTFS Alternate Data Streams

Our analysis confirms that result.dll is a direct evolution of GIFTEDCROOK, the stealer that CERT-UA attributed to UAC-0226 in April 2025.

via trend micro researchtrendmicro.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAC-0226

Our analysis confirms that result.dll is a direct evolution of GIFTEDCROOK, the stealer that CERT-UA attributed to UAC-0226 in April 2025.

via trend micro researchtrendmicro.com
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

2 techniques
T1059.001PowerShellEvidence1

We track the binary payload chain (CVE-2025-8088 to LNK to PowerShell to result.dll ) under SHADOW-EARTH-066 ... Earth Dahu uses Cloudflare Workers as a C&C proxy and relies on script-based tooling (HTA, VBScript, PowerShell).

T1203Exploitation for Client ExecutionEvidence1

The two campaigns examined in this report share the same initial exploit (CVE-2025-8088) and overlapping victimology... Despite CVE-2025-8088 was patched in WinRAR 7.13 in July 2025, yet at the time of writing, multiple threat actor groups continued to build new exploit samples with fresh lure documents and use this vulnerability as a reliable initial access vector against Ukrainian organizations.

Persistence

1 technique
T1547.009Shortcut ModificationEvidence1

We track the binary payload chain (CVE-2025-8088 to LNK to PowerShell to result.dll ) under SHADOW-EARTH-066

Privilege Escalation

1 technique
T1547.009Shortcut ModificationEvidence1

We track the binary payload chain (CVE-2025-8088 to LNK to PowerShell to result.dll ) under SHADOW-EARTH-066

Stealth

2 techniques
T1027Obfuscated Files or InformationEvidence1

SHADOW-EARTH-066 communicates with direct IP-based C&C servers and delivers a compiled x86-64 DLL with PEB-walk API resolution and RC4-encrypted strings.

T1027.007Dynamic API ResolutionEvidence1

SHADOW-EARTH-066 communicates with direct IP-based C&C servers and delivers a compiled x86-64 DLL with PEB-walk API resolution and RC4-encrypted strings.

Command and Control

1 technique
T1071Application Layer ProtocolEvidence1

SHADOW-EARTH-066 communicates with direct IP-based C&C servers ... Earth Dahu uses Cloudflare Workers as a C&C proxy ... C&C infrastructure pattern (Dynamic DNS with Cloudflare Workers) are identical.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Our analysis confirms that result.dll is a direct evolution of GIFTEDCROOK, the stealer that CERT-UA attributed to UAC-0226 in April 2025. The two share the same compiler toolchain, cryptographic framework, anti-analysis checks, and exfiltration protocol... SHADOW-EARTH-066 uses it to deploy an evolved information stealer

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.