BoryptGrab
BoryptGrab is an information stealer targeting Windows users. Trend Micro reported it was distributed through a large campaign abusing more than 100 public GitHub repositories, with ZIP archives masquerading as legitimate software tools, utilities, and game cheats. The operation used SEO-stuffed GitHub README files and deceptive GitHub Pages-style download sites, including a Voicemod Pro lure, to drive victims through redirect chains to fake download pages that generated malicious ZIP archives. Proton66 OOO infrastructure was also linked to a BoryptGrab infostealer operation abusing over 100 public GitHub repositories through SEO manipulation.
The malware is described as a C/C++ stealer that performs anti-analysis checks, including querying registry entries, checking VM-related files, comparing running process names against a predefined list, and attempting to execute with elevated privileges. Infection chains observed in the reporting include DLL sideloading via a malicious libcurl.dll, VBS downloaders that decode hidden PowerShell commands, and .NET loaders. Launchers can download BoryptGrab and additional payloads, pass build names such as Shrek, Leon, and CryptoByte via a "-b" argument, and establish persistence through scheduled tasks. Some related delivery chains also used HeaconLoad, a Golang downloader that maintains persistence via registry entries and scheduled tasks and downloads additional bundles.
BoryptGrab collects extensive data from infected systems. Reported targets include browser data from Chrome, Edge, Firefox, Opera, Brave, Vivaldi, and Yandex; cryptocurrency wallet data from Exodus, Electrum, Ledger Live, Atomic, Binance, Wasabi, and Trezor; system details; screenshots; Telegram files; common files with specific extensions from common directories; and, in newer variants, Discord tokens. The malware uses techniques from public GitHub tools to bypass Chrome App-Bound Encryption and decrypt stored browser credentials. It supports command-line arguments including "--output-path"/"-o" and "--build-name"; if no output path is provided, it creates a staging directory name based on the current time, public IP address, and country code. After collection, it compresses stolen data and uploads the archive to attacker-controlled infrastructure.
Associated payloads observed alongside BoryptGrab include Vidar variants, HeaconLoad, and TunnesshClient, a PyInstaller backdoor that creates a reverse SSH tunnel enabling remote command execution, file movement, and proxying through the infected host. Reporting cited Russian-language comments and infrastructure artifacts as suggesting the operators may be of Russian origin.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
2 techniques
Resource Development
Execution
4 techniques
Execution
The script decodes PowerShell commands, downloads a launcher from a remote server...
Persistence
1 technique
Persistence
Privilege Escalation
3 techniques
Privilege Escalation
Stealth
3 techniques
Stealth
Credential Access
2 techniques
Credential Access
Discovery
3 techniques
Discovery
Collection
3 techniques
Collection
Command and Control
2 techniques
Command and Control
Exfiltration
1 technique
Exfiltration
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer operation abusing more than 100 public GitHub repositories through SEO manipulation.
Information stealer distributed via fake GitHub Pages/SEO lures; harvests browser data, crypto wallet info, system info; can capture screenshots, collect files, and steal Telegram/Discord data and passwords.
C/C++ information stealer distributed via malicious GitHub repositories and ZIP archives masquerading as tools/cheats. Collects browser credentials/data (Chrome/Edge/Firefox/Opera/Brave/Vivaldi/Yandex), Telegram data, Discord tokens (newer variants), screenshots, system info, and files by extension; steals data from multiple desktop crypto wallets (e.g., Exodus, Electrum, Ledger Live, Atomic, Binance, Wasabi, Trezor). Stages data locally, compresses it, and uploads to attacker infrastructure; includes anti-analysis/VM checks and attempts privilege elevation.
Information-stealing malware targeting Windows users, distributed via deceptive GitHub Pages.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.