logo

Massive GitHub malware operation spreads BoryptGrab stealer

ID: 66fb73ea-fdde-5ef9-82ac-d7835422ab42

STIX ID: report--66fb73ea-fdde-5ef9-82ac-d7835422ab42

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-03-08

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Trend Micro and SecurityAffairs detail a large-scale campaign distributing the BoryptGrab information stealer through over 100 deceptive GitHub repositories and ZIP downloads that masquerade as software tools or game cheats; the stealer harvests browser credentials, crypto wallet data, system information and user files, and some variants deploy additional payloads including a PyInstaller reverse-SSH backdoor (TunnesshClient) and the HeaconLoad downloader.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.