GIFTEDCROOK Attack Chain Uses WinRAR ADS and Reflective Loading to Target Browser Data
A newer GIFTEDCROOK attack chain tied to UAC-0226 uses weaponized WinRAR archives, NTFS Alternate Data Streams, a Startup-folder shortcut, and reflective loading to run an information stealer on Windows systems. The campaign focuses on Ukrainian military- …