Trend Micro Identifies 100+ GitHub Repos Distributing BoryptGrab Stealer
Mar 7, 2026 // 16:40 - Norina Velotta


Trend Micro has identified an active campaign where over 100 GitHub repositories were used to distribute a new information-stealing malware dubbed BoryptGrab. 

Campaign Strategy

The attackers utilize SEO-optimized GitHub repositories and lookalike download pages to trick users into downloading malicious files. They primarily target Windows users looking for: 

  • Gaming tools: Cheats, hacks, and aimbots for games like Valorant, Counter-Strike 2, and Call of Duty.
  • Cracked software: “Pro” or “Free” versions of utilities like Filmora, Krita, and Voicemod.
  • Performance boosters: Tools claiming to increase FPS or system speed. 

Malware Capabilities

BoryptGrab is a sophisticated stealer designed to harvest sensitive data from infected machines, including: 

  • Browsers: Steals login credentials, autofill data, and history from major browsers including Chrome, Edge, and Brave.
  • Crypto Wallets: Targets nearly three dozen desktop wallets and extensions, such as Atomic Wallet, Coinomi, and Trezor Suite.
  • Messaging: Extracts files from Telegram and tokens from Discord.
  • System Access: In some variants, it drops a secondary backdoor called TunnesshClient, which establishes a reverse SSH tunnel to allow attackers remote command execution. 

Origin and Indicators

Analysis of the code and associated infrastructure reveals several indicators of a Russian-speaking origin: 

  • The malware’s code contains Russian-language comments and log messages.
  • IP addresses used for command-and-control (C2) are located in Russia.
  • The campaign leverages multiple execution methods, including DLL sideloading and VBS scripts, to evade standard security filters. 

Security experts at Broadcom (Carbon Black)recommend blocking all suspicious ZIP downloads from unverified GitHub Pages and ensuring cloud-based reputation scanning is active to detect shifting payloads.

#100+  #boryptgrab  #distributing  #github  #identifies  #micro  #news  #repos  #stealer:  #trend   —   News