logo

BoryptGrab Stealer Spreads via Fake GitHub Repositories, Stealing Browser and Crypto Wallet Data

ID: f1fdadd2-f55c-57fa-b212-8e2c36f7d16e

STIX ID: report--f1fdadd2-f55c-57fa-b212-8e2c36f7d16e

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

BoryptGrab is an active data‑stealing campaign that lures victims to fake GitHub pages offering cracked or popular tools; visits are funneled through base64/AES‑encoded redirections to dynamically generated download pages that deliver malicious ZIPs. Payload variants use DLL sideloading, obfuscated VBS/PowerShell downloaders, Defender exclusion modifications, and VM/sandbox checks to fetch an info‑stealer that harvests browser credentials, cookies, >30 desktop and extension crypto wallets, messaging tokens, screenshots, and system files, then exfiltrates data; a PyInstaller backdoor (TunnesshClient) can establish a reverse SSH tunnel for remote access and proxying. Defenders should watch for unexpected Defender exclusions, scheduled tasks, and unusual outbound traffic to unknown servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.