logo

BoryptGrab Malware Abuses GitHub to Steal Browser and Crypto Wallet Data

ID: f9722f3d-2ca7-5e9d-8422-3a5ee37f7ea3

STIX ID: report--f9722f3d-2ca7-5e9d-8422-3a5ee37f7ea3

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

BoryptGrab is an active Windows information‑stealer campaign that uses SEO‑poisoned fake GitHub repositories to trick users into downloading malicious ZIPs which deploy layered downloaders and side‑loading chains to install stealers (and sometimes Vidar variants) and a TunnesshClient SSH backdoor; it targets browser credentials, desktop and extension cryptocurrency wallets, Telegram/Discord data, screenshots and user files, and exfiltrates collected data to attacker servers, with observable indicators like build names (Shrek, CryptoByte, etc.) and specific beaconing ports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.