Massive GitHub malware operation spreads BoryptGrab stealer
ID: 66fb73ea-fdde-5ef9-82ac-d7835422ab42
STIX ID: report--66fb73ea-fdde-5ef9-82ac-d7835422ab42
Feed Name: Security Affairs
Threat Score
Trend Micro and SecurityAffairs detail a large-scale campaign distributing the BoryptGrab information stealer through over 100 deceptive GitHub repositories and ZIP downloads that masquerade as software tools or game cheats; the stealer harvests browser credentials, crypto wallet data, system information and user files, and some variants deploy additional payloads including a PyInstaller reverse-SSH backdoor (TunnesshClient) and the HeaconLoad downloader.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
