Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Over 100 GitHub Repositories Distributing BoryptGrab Stealer
    Cybersecurity

    Over 100 GitHub Repositories Distributing BoryptGrab Stealer

    adminBy adminMarch 7, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Infostealers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new information stealer has been distributed through a network of more than 100 GitHub repositories, Trend Micro reports.

    Dubbed BoryptGrab, the malware can harvest browser and cryptocurrency wallet data, along with system information and user files.

    Additionally, certain iterations of the stealer can drop a backdoor dubbed TunnesshClient, which uses an SSH tunnel for command-and-control (C&C) communication.

    Trend Micro’s investigation into BoryptGrab revealed the existence of multiple ZIP archives masquerading as free software tools that have been distributed since late 2025 through the GitHub repositories.

    All identified binaries contained similar Russian-language comments and URL-fetching logic, although the malware’s execution logic was not the same for all ZIP archives.

    In some cases, DLL sideloading was used for execution, leveraging an executable within the archive, while in others, VBS Script was used to fetch the launcher’s executable. A .NET executable, a Golang downloader named HeaconLoad, and other execution paths were also observed.

    Advertisement. Scroll to continue reading.

    BoryptGrab is a C/C++ information stealer that includes VM and anti-analysis checks and attempts to execute with elevated privileges.

    It can harvest information from close to a dozen browsers, uses Chrome App Bound Encryption techniques from two GitHub repositories, and downloads a Chromium helper to collect information from the targeted browsers.

    It can also collect data from desktop cryptocurrency wallet applications and browser extensions, harvest system information, take screenshots, and collect files with specific extensions.

    Additionally, Trend Micro discovered that the stealer can obtain Telegram files, browser passwords, and, in newer iterations, Discord tokens. All the harvested information is archived and sent to the attacker’s C&C server.

    Some of the identified variants also deploy the TunnesshClient backdoor, which in other cases is dropped using different downloaders.

    TunnesshClient can execute commands provided by the attacker via a reverse SSH tunnel. Based on these, the malware acts as a SOCKS5 proxy, executes shell commands, lists files, searches for files, uploads and downloads files, or sends entire folders to the attacker’s server.

    “The BoryptGrab campaign illustrates an evolving threat ecosystem targeting users through deceptive software downloads and fake GitHub repositories,” Trend Micro notes, adding that the operation shows an increasing level of engineering sophistication.

    Related: ‘Arkanix Stealer’ Malware Disappears Shortly After Debut

    Related: ‘SolyxImmortal’ Information Stealer Emerges

    Related: Lumma Stealer Activity Drops After Doxxing

    Related: Hundreds Targeted in New Atomic macOS Stealer Campaign

    BoryptGrab Distributing GitHub Repositories Stealer
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleFirefox Nightly for Developers 150.0a1 APK Download by Mozilla
    Next Article I switched back to Samsung Tizen and it’s so much better than Google TV
    admin
    • Website

    Related Posts

    Cursor Automations turns code review and ops into background tasks

    March 7, 2026

    Termite ransomware breaches linked to ClickFix CastleRAT attacks

    March 7, 2026

    Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model

    March 7, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google I/O 2026: How to Watch and What We Know so Far

    March 7, 2026

    Cursor Automations turns code review and ops into background tasks

    March 7, 2026

    Why a long HDMI cable is the best thing I’ve bought in months

    March 7, 2026

    Termite ransomware breaches linked to ClickFix CastleRAT attacks

    March 7, 2026
    Categories
    • Blogging (34)
    • Cybersecurity (657)
    • Privacy & Online Earning (93)
    • SEO & Digital Marketing (415)
    • Tech Tools & Mobile / Apps (801)
    • WiFi / Internet & Networking (114)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google I/O 2026: How to Watch and What We Know so Far

    March 7, 2026

    Cursor Automations turns code review and ops into background tasks

    March 7, 2026

    Why a long HDMI cable is the best thing I’ve bought in months

    March 7, 2026
    Most Popular
    • Google I/O 2026: How to Watch and What We Know so Far
    • Cursor Automations turns code review and ops into background tasks
    • Why a long HDMI cable is the best thing I’ve bought in months
    • Termite ransomware breaches linked to ClickFix CastleRAT attacks
    • I switched back to Samsung Tizen and it’s so much better than Google TV
    • Over 100 GitHub Repositories Distributing BoryptGrab Stealer
    • Firefox Nightly for Developers 150.0a1 APK Download by Mozilla
    • House of Moto Indigo offers ‘depth’ to Motorola’s future, alongside a GrapheneOS partnership
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.