logo

New CGrabber and Direct-Sys Malware Spread Through GitHub ZIP Files

ID: b44d74b3-555c-5d8d-b2c0-3bd6fd3a4d59

STIX ID: report--b44d74b3-555c-5d8d-b2c0-3bd6fd3a4d59

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-04-17

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Cyderes researchers uncovered a sophisticated multi-stage malware campaign delivered via GitHub-hosted ZIP archives that leverages DLL sideloading to launch a Direct-Sys Loader which evades analysis (including direct syscalls and VM/sandbox checks) and then deploys the CGrabber Stealer to harvest browser credentials, credit cards, cookies, private keys from 150+ crypto apps, and data from messaging and VPN clients; stolen data is ChaCha20-encrypted and the malware avoids systems in Commonwealth of Independent States countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.