UAC-0226 hacking group is involved in a cyber-espionage campaign targeting critical sectors in Ukraine.
The group is using GIFTEDCROOK stealer to gather intelligence from military innovation hubs, armed forces, law enforcement entities, and government institutions.
The cyber-espionage activities have been observed since February 2025, with an increase in attacks against Ukraine.
Phishing emails with macro-enabled Excel files are used as the initial attack vector, and GIFTEDCROOK steals browser data and exfiltrates it via Telegram.