BoryptGrab Stealer Spreads via Fake GitHub Repositories, Stealing Browser and Crypto Wallet Data
ID: f1fdadd2-f55c-57fa-b212-8e2c36f7d16e
STIX ID: report--f1fdadd2-f55c-57fa-b212-8e2c36f7d16e
Feed Name: cybersecurityNews.com
BoryptGrab is an active data‑stealing campaign that lures victims to fake GitHub pages offering cracked or popular tools; visits are funneled through base64/AES‑encoded redirections to dynamically generated download pages that deliver malicious ZIPs. Payload variants use DLL sideloading, obfuscated VBS/PowerShell downloaders, Defender exclusion modifications, and VM/sandbox checks to fetch an info‑stealer that harvests browser credentials, cookies, >30 desktop and extension crypto wallets, messaging tokens, screenshots, and system files, then exfiltrates data; a PyInstaller backdoor (TunnesshClient) can establish a reverse SSH tunnel for remote access and proxying. Defenders should watch for unexpected Defender exclusions, scheduled tasks, and unusual outbound traffic to unknown servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
