Netskope Threat Labs

Giftedcrook

ATP Sandbox Adv. Heuristics

Giftedcrook is a stealer written in C/C++ that the UAC-0226 threat actor uses to target browser databases and exfiltrate the collected data through Telegram.

First seen
July 2025
Last seen
September 2026
Alert Name
Document-Excel.Trojan.Giftedcrook
Document-PDF.Trojan.Giftedcrook
Document-Word.Trojan.Giftedcrook
Script-PowerShell.Trojan.Giftedcrook
Shortcut.Trojan.Giftedcrook
Win32.Trojan.Giftedcrook
Win64.Spyware.Giftedcrook