Researchers at Cyderes reported a malware campaign abusing GitHub user attachment links hosted on GitHub’s CDN to distribute ZIP archives that launch a five-stage infection chain. The archives deliver a novel loader, Direct-Sys Loader, and an infostealer, CGrabber Stealer, using signed binary sideloading, ChaCha20-based decryption, reflective loading, direct syscalls, and APC-based process injection into legitimate Microsoft-signed processes including Launcher_x64.exe and Dllhost.exe.
CGrabber Stealer was observed performing repeated anti-sandbox and anti-analysis checks, skipping systems configured for CIS locales, and contacting a remote command-and-control server before stealing data from browsers, cryptocurrency wallets, browser extensions, VPN clients, password managers, messaging applications, and other software. The stolen information is packaged into ZIP archives for exfiltration, and researchers said shared encryption routines and evasion logic indicate the loader and stealer were likely built by the same author; defenders were urged to watch for DLL sideloading, syscall stubs, suspicious outbound POST traffic, and attempts to patch AMSI and ETW.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
SC Media covered Cyderes' findings on the campaign distributing CGrabber Stealer via GitHub user attachment links. The article summarized the malware’s data theft targets, including browsers, crypto wallets, VPNs, password managers, messaging apps, and other applications.
Cyderes published technical details linking the loader and stealer to a likely common author based on shared encryption routines and anti-analysis logic. The report also recommended monitoring for syscall stubs, DLL sideloading, suspicious outbound POST traffic, and AMSI and ETW patching activity.
Cyderes reported a malware campaign abusing GitHub user attachment links on GitHub’s CDN to deliver ZIP archives containing the novel Direct-Sys Loader and CGrabber Stealer. The researchers documented a five-stage infection chain using signed binary sideloading, anti-analysis checks, ChaCha20-based decryption, reflective loading, direct syscalls, and APC-based process injection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 93 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.