Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » From browser steelers to intelligence gathering tools
Celebrities

From browser steelers to intelligence gathering tools

By June 28, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

June 28, 2025Ravi LakshmananMalware/Cyber ​​War

GiftedCrook Malware

The threat actors behind the GiftedCrook malware have made important updates to transform malicious programs from basic browser data steelers into powerful intelligence gathering tools.

“The recent campaign in June 2025 shows that it strengthens its talented ability to remove a wide range of sensitive documents from targeted personal devices, including potentially unique files and browser secrets,” Arctic Wolf Labs said in a report published this week.

“This change in functionality, combined with the contents of the fishing rack, […] It proposes a strategic focus on intelligence newsletters from Ukrainian government and military groups. ”

GiremedCrook was first documented in early April 2025 by the Ukrainian Computer Emergency Response Team (CERT-UA) in connection with a campaign targeting military entities, law enforcement and local autonomous organizations.

Cybersecurity

Activities caused by hacking groups tracking as UAC-0226 include the use of phishing emails that contain Microsoft Excel documents for macro races that act as conduits for deploying GiftedCrook.

Core information stealing malware is designed to steal cookies, browsing history and authentication data from popular web browsers such as Google Chrome, Microsoft Edge, and Mozilla Firefox.

An analysis of Arctic Wolf artifacts revealed that Steeler began as a demo in February 2025 and later acquired new features in versions 1.2 and 1.3.

These new iterations include the ability to harvest documents and files that are less than 7 MB in size, particularly looking for files that have been created or modified within the last 45 days. Malware specially searches for the following extensions: .doc, .docx, .rtf, .pptx, .ppt, .csv, .xls, .xlsx, .jpeg, .jpg, .png, .pdf, .odt, .rar, .zip, .eml, .txt, .txt, .txt, .txt.

Email campaigns leverage military-themed PDF lures to tempt users to click on the Mega cloud storage link that hosts a macro-enabled Excel workbook (“Academy”) (“GiftedCrook downloaded when recipients turn on macros. Many users are unaware of how macro-enabled Excel files are common in phishing attacks. People often expect work emails, especially spreadsheets that look official or government-related, so they slip past defenses.

The captured information is bundled in a zip archive and stretched to an attacker-controlled telegram channel. If the total archive size exceeds 20 MB, it is classified into multiple parts. By sending stolen ZIP archives in small chunks, GilevedCrook avoids detection and skipping around traditional network filters. In the final stage, a batch script is executed to clear the steeler traces from the compromised host.

Cybersecurity

This not only steals passwords and tracks online behavior, but also provides targeted cyberspy. New features of malware that sift through recent files such as PDFs, spreadsheets, and even VPN configurations and grab documents refer to the bigger goal: collecting intelligence. For those who work in public sector roles or handle sensitive internal reports, this type of document steeler poses real risks not only to individuals but to the entire connected network.

“The timing of the campaign discussed in this report shows a clear alignment with geopolitical events, particularly recent negotiations between Istanbul and Russia,” Arctic Wolf said.

“The progression from a simple qualification theft of GiftedCrook version 1 to a comprehensive documentation and data removal for versions 1.2 and 1.3 reflects coordinated development efforts in which malware features enhance data collection from Ukrainian breach systems according to geopolitical purposes.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFacebook’s new AI tool asks you to upload your photos for story ideas, causing privacy concerns
Next Article Is a cat the only animal?

Related Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Cardi B, Fat Joe and other musicians react

Trending Posts

BTS’s “Come Over” was chosen as this week’s best new song

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Cardi B, Fat Joe and other musicians react

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.