BoryptGrab is a Windows information stealer distributed through large-scale brand-impersonation and fake software download campaigns, particularly via malicious GitHub repositories, deceptive landing pages, and trojanized archives. It is associated with financially motivated activity and has been linked to operations that abuse search-engine visibility and trusted developer platforms to lure users seeking free tools, security products, developer utilities, cryptocurrency software, and gaming-related downloads.
The malware is designed for rapid data theft rather than long-term access. Reported variants collect browser credentials, cookies, payment-related data, browser session material, cryptocurrency wallet data, messaging application data, Windows Credential Manager secrets, screenshots, host profiling information, and selected files likely to contain passwords, wallet backups, seed phrases, keys, or recovery material. Documented targeting includes numerous Chromium-based and Gecko-based browsers, multiple cryptocurrency wallet applications and extensions, and applications such as Telegram, Discord, Steam, and Meta Max.
BoryptGrab has been observed delivered through DLL sideloading chains in which a legitimate signed executable loads a malicious library that decrypts or reconstructs the stealer and executes it in memory. Other reported delivery chains include script-based downloaders and loaders that retrieve BoryptGrab as a later stage. Some campaigns used fake GitHub repositories with polished README content and concealed download links that redirected victims to spoofed download portals serving frequently regenerated archives. Earlier reporting also tied BoryptGrab distribution to SEO manipulation across large numbers of public repositories.
The stealer includes anti-protection and anti-analysis tradecraft in some observed variants. Reported capabilities include bypassing Chrome App-Bound Encryption through code injection to obtain browser decryption material, process and environment checks associated with anti-analysis, and privilege-related execution logic. Some campaigns using BoryptGrab also deployed additional malware families or backdoor components, but BoryptGrab itself is primarily characterized as a smash-and-grab infostealer focused on immediate collection and exfiltration.
Attribution to a specific threat group remains unconfirmed. Multiple investigations assess with high confidence that recent in-memory stealers used in fake GitHub software campaigns share the BoryptGrab codebase or lineage first documented by Trend Micro. Operational artifacts and infrastructure patterns have suggested a likely Russian-speaking, financially motivated operator in some campaigns, but same-actor attribution across all BoryptGrab-related activity is low confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Researchers say the malware targets passwords, cookies, payment information, browser sessions, and wallet credentials from 19 browsers and 32 cryptocurrency wallets.
Other modules copy Telegram session data from every attached drive, pull Discord tokens across three release channels... and scan Steam helper process memory for live session tokens.
Researchers say the malware targets passwords, cookies, payment information, browser sessions, and wallet credentials from 19 browsers and 32 cryptocurrency wallets.
Researchers say the malware targets passwords, cookies, payment information, browser sessions, and wallet credentials from 19 browsers and 32 cryptocurrency wallets. It also steals data from Telegram, Discord, Steam, Windows Credential Manager, and other applications.
A 41-entry wallet path table covers roughly 32 wallet brands. The grabber also sweeps Desktop and Documents for files named after passwords, seeds, and recovery data.
Researchers say the malware targets passwords, cookies, payment information, browser sessions, and wallet credentials from 19 browsers and 32 cryptocurrency wallets.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer used in fake GitHub software repositories to silently harvest sensitive data, including passwords, cookies, payment information, browser sessions, cryptocurrency wallet credentials, and data from applications such as Telegram, Discord, Steam, and Windows Credential Manager. It can also bypass Chrome App-Bound Encryption via code injection.
Mentioned only as background in prior fake GitHub repository attacks involving a BoryptGrab-lineage stealer.
Mentioned only as comparison/background for similar fake repository incidents.
An in-memory infostealer delivered via brand-impersonation GitHub repositories and fake download pages. It uses a signed WinGUP updater to side-load a trojanized libcurl.dll, reconstructs and executes its payload entirely in memory using COM-based staging, and runs 11 theft modules targeting browser credentials and cookies, wallet data, Telegram sessions, Discord tokens, Meta Max credentials, Steam session tokens, and sensitive files before exfiltrating data to a hardcoded C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.