logo

Fake GitHub Repositories Unleash BoryptGrab Stealer and TunnesshClient Backdoor

ID: 9d3a4b91-215d-549a-820a-b1b52fdade44

STIX ID: report--9d3a4b91-215d-549a-820a-b1b52fdade44

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-09

Date Updated: 2026-04-23

Author: Ddos

...
...

BoryptGrab is a widespread campaign that lures victims via SEO-optimized GitHub repositories offering fake “free” tools; the downloaded ZIPs install an infostealer that harvests browser credentials, crypto wallets, messaging tokens, and files, and may deploy a PyInstaller backdoor (TunnesshClient) that creates reverse SSH tunnels and a SOCKS5 proxy for attacker traffic. TrendMicro researchers observed dozens of repositories and code/infrastructure clues (Russian-language comments and Russia-hosted IPs) linking the operation to Russian-speaking actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.