
Trend Micro has identified an active campaign where over 100 GitHub repositories were used to distribute a new information-stealing malware dubbed BoryptGrab.
Campaign Strategy
The attackers utilize SEO-optimized GitHub repositories and lookalike download pages to trick users into downloading malicious files. They primarily target Windows users looking for:
Malware Capabilities
BoryptGrab is a sophisticated stealer designed to harvest sensitive data from infected machines, including:
Origin and Indicators
Analysis of the code and associated infrastructure reveals several indicators of a Russian-speaking origin:
Security experts at Broadcom (Carbon Black)recommend blocking all suspicious ZIP downloads from unverified GitHub Pages and ensuring cloud-based reputation scanning is active to detect shifting payloads.
#100+ #boryptgrab #distributing #github #identifies #micro #news #repos #stealer: #trend — News
© Bulletproof Servers. All rights reserved.