BoryptGrab is a Windows information-stealer family distributed through large-scale brand-impersonation campaigns using fraudulent GitHub repositories, search-engine optimization, and fake software download pages. Delivered archives commonly abuse DLL side-loading with legitimate signed executables to launch loaders or the stealer, including memory-resident payload execution in some campaigns. BoryptGrab targets browser credentials, cookies, payment data, browser sessions, cryptocurrency-wallet data, Windows Credential Manager secrets, and session tokens or local data associated with messaging and gaming applications. It also collects host information, screenshots, and files selected by sensitive-name keywords or extensions. The malware can bypass Chrome App-Bound Encryption through code injection into browser processes, compress collected data, and exfiltrate it to attacker-controlled infrastructure. Some BoryptGrab delivery chains establish persistence through scheduled tasks or registry-based mechanisms and may deploy additional downloaders or backdoors. The family has been associated with opportunistic, financially motivated campaigns targeting Windows users seeking software, utilities, security products, cryptocurrency tools, and game-related downloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Researchers say the malware targets passwords, cookies, payment information, browser sessions, and wallet credentials from 19 browsers and 32 cryptocurrency wallets.
Other modules copy Telegram session data from every attached drive, pull Discord tokens across three release channels... and scan Steam helper process memory for live session tokens.
Researchers say the malware targets passwords, cookies, payment information, browser sessions, and wallet credentials from 19 browsers and 32 cryptocurrency wallets.
Researchers say the malware targets passwords, cookies, payment information, browser sessions, and wallet credentials from 19 browsers and 32 cryptocurrency wallets. It also steals data from Telegram, Discord, Steam, Windows Credential Manager, and other applications.
« Rapuncel stealer — Vol de credentials, wallets crypto, Discord, Steam, Telegram, Windows Credential Manager » and collection artifacts include a “Filegraber” directory.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer assessed by Delphos Labs to be the likely predecessor or family variant of Rapuncel; it was previously distributed through hundreds of fake GitHub repositories.
Information stealer family to which Rapuncel may be related or a variant, according to the researchers cited.
Stealer lié de manière possible à la campagne Rapuncel. Les similitudes mentionnées concernent la marque passathook-cs2, la livraison SEO via GitHub, des artefacts de collecte identiques et le contournement du chiffrement app-bound de Chrome; les échantillons, infrastructures C2 et builds restent distincts.
A credential-stealing malware family previously distributed through fake GitHub repositories. It is assessed as related to, but not the same build as, Rapuncel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.