{"id":60264,"date":"2026-03-05T00:00:00","date_gmt":"2026-03-05T00:00:00","guid":{"rendered":"urn:uuid:3503a9ec-9ac1-d90d-2d0d-e22b946ab38d"},"modified":"2026-03-05T00:00:00","modified_gmt":"2026-03-05T00:00:00","slug":"new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/","title":{"rendered":"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/AsyncRAT-cover:Large?qlt=80\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"description\" content=\"The BoryptGrab campaign uses fake SEO\u2011optimized GitHub repositories and deceptive download pages to distribute a data\u2011stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"malware,research,articles, news, reports,cyber threats,cyber crime\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2026-03-05\"> <meta property=\"article:tag\" content=\"malware\"> <meta property=\"article:section\" content=\"research\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/c\/boryptgrab-stealer-targets-users-via-deceptive-github-pages.html\"> <title>New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages | Trend Micro (US)<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendmicro\/clientlibs\/trendmicro-core-2\/clientlibs\/header-footer.min.cc255fd374a145c2653503eb2da45983.css\" type=\"text\/css\">\n<link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.47ce60d92d94610907e7a2cbd6fbca69.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/c\/boryptgrab-stealer-targets-users-via-deceptive-github-pages.html\"><br \/>\n<meta property=\"og:title\" content=\"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages\"><br \/>\n<meta property=\"og:description\" content=\"The BoryptGrab campaign uses fake SEO\u2011optimized GitHub repositories and deceptive download pages to distribute a data\u2011stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/AsyncRAT-cover.png\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages\"><br \/>\n<meta name=\"twitter:description\" content=\"The BoryptGrab campaign uses fake SEO\u2011optimized GitHub repositories and deceptive download pages to distribute a data\u2011stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/AsyncRAT-cover.png\"> <meta name=\"user-country-code\" content=\"US\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"50.909031653563\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layers *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"697299672\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"9.5\">\n<div class=\"article-details\" role=\"heading\" readability=\"39\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Malware<\/p>\n<p class=\"article-details__description\">The BoryptGrab campaign uses fake SEO\u2011optimized GitHub repositories and deceptive download pages to distribute a data\u2011stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.<\/p>\n<p class=\"article-details__author-by\">By: Mingyue Shirley Yang <time class=\"article-details__date\">Mar 05, 2026<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<div class=\"article-details__icons\"> <!--Add This--> <\/p>\n<div class=\"a2a_kit a2a_default_style\" data-a2a-icon-color=\"#717172\"> <a class=\"a2a_dd addthis_link\" href=\"https:\/\/www.addtoany.com\/share\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/share-more.svg\" class=\"svg-icon\" alt=\"Share\"> <\/a> <a class=\"a2a_button_print addthis_link\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/printer.svg\" class=\"svg-icon\" alt=\"Print\"> <\/a> <\/div>\n<p> <!--Add to Folio--> <!--Subscribe--> <\/div>\n<\/div><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-lg-8 col-lg-push-2\"> <\/p>\n<div class=\"richText\" readability=\"46\">\n<div readability=\"37\">\n<ul>\n<li><span class=\"rte-red-bullet\">BoryptGrab is a newly identified stealer that harvests browser data, cryptocurrency wallet information, and system information. It is also capable of capturing screenshots, collecting common files, and extracting Telegram information, Discord tokens, and passwords.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The malware is distributed through a large number of public Github repositories that purport to offer software tools for free, using SEO keywords to attract victims. The infection chain is initiated when ZIP file is downloaded from a fake GitHub download page.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Malware code from different stages of the attack contains Russian-language comments and\/or log messages. IP addresses associated with the campaign are also located in Russia, suggesting a possible origin for the attacker. Different builds of the malware have also been observed in the campaign.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">TunnesshClient is a new backdoor delivered during the attack chain. It is a PyInstaller executable that establishes a reverse SSH tunnel to communicate with the attacker and acts as a SOCKS5 proxy. This campaign can also deliver variants of the existing Vidar stealer with code obfuscation.<\/span><\/li>\n<\/ul>\n<p>We recently found the existence of a new stealer binary that collects browser and cryptocurrency wallet data, system information, and common files, among others. We designated this new stealer BoryptGrab. Certain variants of the stealer can download a PyInstaller backdoor, which we refer to as TunnesshClient. TunnesshClient establishes a reverse Secure Shell (SSH) tunnel to enable comunication with the attacker.<\/p>\n<p>By tracing the infection chain, we were able to observe several ZIP archive files in the wild (all with similar naming conventions) that masquerade as common software tools (including gaming cheat hacks). As the \u201c<i>github-io<\/i>\u201d patterns in some ZIP file names suggest, searching for the software tool patterns leads to over a hundred public Github repositories delivering malware. The earliest ZIP file we identified dates to late 2025, while the initial commit of the earliest GitHub repository account was made in April 2025.<\/p>\n<p>&nbsp;The following list is a sample of ZIP files without \u201cgithub-io\u201d in their filename:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">valorant performance boost fps booster 5.4.9.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">voicemod pro download tool 8.2.1 1 .zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">wondershare info feel 8.4.3.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sk1nchangerforcs24pc 5.8.0.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">cod black ops 6 aimbot with esp tool 4.2.4.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">abi free esp tool download 9.0.0.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">arenabreakoutcheat 8.6.2.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">git deployer app 7.7.2.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">valorant skin tool 4.1.3.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">filmora watermark remover 8.6.7.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sk1nchangerforcs24pc 2.9.5.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">r6siege free esp tool 1.8.9.zip<\/span><\/li>\n<\/ul>\n<p>Meanwhile, the following are examples of ZIP files with \u201cgithub-io\u201d in their filename:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">vmware-download-github-io-4.83.4.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">passathook-cs2-github-io-1.96.4.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">meta-skins-github-io-6.98.9.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">cs2-skin-changer-premium-github-io-1.88.9.zip<\/span><\/li>\n<li><span class=\"rte-red-bullet\">passathook-cs2-github-io-2.56.2.zip<\/span><\/li>\n<\/ul>\n<p>In the following sections, we will provide detailed analysis for the delivered BoryptGrab stealer, the TunnesshClient backdoor, and other malware observed in the campaign. We will also include in-depth analysis of the attack chains and delivery routes of the malware. The Russian comments, log messages, and IP addresses found during different stages of the attack chain indicates potential a Russian background for the threat actor.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <a id=\"320bba\" data-modal-title=\"Figure 1. Attack chain for the BoryptGrab campaign\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig1.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig1.png\" alt=\"Figure 1. Attack chain for the BoryptGrab campaign\"> <\/a> <\/p>\n<p><figcaption>Figure 1. Attack chain for the BoryptGrab campaign<\/figcaption><\/p>\n<\/figure><\/div>\n<div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>The malware was initially distributed through public Github repositories offering free, seemingly legitimate software tools. The README files for some of these repositories contain SEO keywords designed to increase their ranking for results returned by search engines. An example is a repository is located at <u>hxxps:\/\/github[.]com\/Voicemod-Pro-Download-Tool<\/u>, which delivers a fake Voicemod Pro tool. The Google search rankings for this repository was just below the legitimate result.<b> <\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"221481\" data-modal-title=\"Figure 2. README page for the malicious Voicemod Pro Github repository\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig2.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig2.png\" alt=\"Figure 2. README page for the malicious Voicemod Pro Github repository\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 2. README page for the malicious Voicemod Pro Github repository<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>The README of the fake Voicemod Pro Github repository contains the download link to the <u>hxxps:\/\/voicemod-pro-download-tool.github[.]io\/.github\/<\/u> page. The source code for this download page is located at <u>hxxps:\/\/github[.]com\/Voicemod-Pro-Download-Tool\/.github<\/u> , where it masquerades as a legitimate <i>.github<\/i> directory.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <a id=\"bf70fb\" data-modal-title=\"Figure 3. Code for the fake download tool in the \u201c.github\u201d repository\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig3.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig3.png\" alt=\"Figure 3. Code for the fake download tool in the \u201c.github\u201d repository\"> <\/a> <\/p>\n<p><figcaption>Figure 3. Code for the fake download tool in the \u201c.github\u201d repository<\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>The <i>index.htm<\/i> web page contains Russian comments and redirects to the <i>home.html<\/i> page. The <i>home.html<\/i> page fetches and decodes a base64-encoded URL from a link hardcoded in its source code (i.e. <u>hxxps:\/\/kiamatka[.]com\/kaiok.kakman<\/u> in the current sample). It then redirects to the decoded URL.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"0afe64\" data-modal-title=\"Figure 4. Fetch and base64-decode a URL used for redirection in home.html\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig4.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig4.png\" alt=\"Figure 4. Fetch and base64-decode a URL used for redirection in home.html\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 4. Fetch and base64-decode a URL used for redirection in home.html<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>Finally, the intermediate URL redirects to the <u>hxxps:\/\/best-tinted[.]com\/github-download.html<\/u> web page that generates a ZIP file to deliver the malware.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"27af51\" data-modal-title=\"Figure 5. Fake Github download page that generates the malicious ZIP file\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig5.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig5.png\" alt=\"Figure 5. Fake Github download page that generates the malicious ZIP file\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 5. Fake Github download page that generates the malicious ZIP file<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"45.5\">\n<div readability=\"36\">\n<p>Although the hardcoded links in the source code and the fetched intermediate URLs vary across the GitHub repositories we identified, similar Russian-language comments and URL-fetching logic were also present in other GitHub repositories we found for this campaign. Many of these repositories also fake different tools , which lead to the same web pages that generate malicious ZIP files. The <i>index.html<\/i> files in some GitHub variants (e.g. <u>hxxps:\/\/github[.]com\/PassFab-4WinKey-Windows-Password-Reset<\/u>) send tracking information to the attacker.<\/p>\n<p>Commit history for a few GitHub repositories (such as <u>hxxps:\/\/github[.]com\/Yim-Mod-Menu\/.github<\/u>) show the deletion of a <i>script.js<\/i> file. The deleted file fetches a URL from an intermediate link and then redirects to the fetched URL.<\/p>\n<p>In other GitHub repositories, <i>scripts.js<\/i> files are used to fetch, AES-decrypt, and redirect to a URL (such as <u>hxxps:\/\/github[.]com\/Arena-Breakout-Infinite-ESP\/.github<\/u>). The <i>scripts.js<\/i> files use Base64-encoded links to fetch the encrypted URLs.<\/p>\n<p>There were also several GitHub repository variants (e.g. <u>hxxps:\/\/github[.]com\/Graphic-Editor-Krita\/.github<\/u>) with recent commits that added Python scripts to simulate the download process.<\/p>\n<p>A list of GitHub repositories we discovered for this campaign is included in the IoC section.<\/p>\n<p>The distributed ZIP file variants can contain an executable that side-loads a <i>libcurl.dll<\/i> file (SHA256: fa767391b99865f8533efc1fe6dfa6175215718679fb00ca85fc13c3bd4ae4b7).<\/p>\n<p>The <i>libcurl.dll<\/i> file (SHA256: fa767391b99865f8533efc1fe6dfa6175215718679fb00ca85fc13c3bd4ae4b7) loads a payload (SHA256: d295720bc0c1111ce1c3d8b1bc1b36ba840f103b3ca7e95a5a8bf03e2cc44fe5) from its resource section. It then decrypts a launcher payload from its resource section using XOR operations and the AES algorithm in CBC mode.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"86b1c2\" data-modal-title=\"Figure 6. The launcher payload is loaded from its resource section by libc.dll \" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig6.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig6.png\" alt=\"Figure 6. The launcher payload is loaded from its resource section by libc.dll \"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 6. The launcher payload is loaded from its resource section by libc.dll <\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"7c4ff0\" data-modal-title=\"Figure 7. The launcher payload is decrypted by libc.dll\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig7.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig7.png\" alt=\"Figure 7. The launcher payload is decrypted by libc.dll\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 7. The launcher payload is decrypted by libc.dll<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"36\">\n<div readability=\"17\">\n<p>The <i>libcurl.dll<\/i> file executes the <i>EntryWrapper<\/i> export function from the decrypted launcher payload.<\/p>\n<p>The decrypted launcher payload, which uses XOR-decryption to obfuscate the URLs for its download targets, downloads the BoryptGrab stealer (:5466\/api\/chromelevator).<\/p>\n<p>Some launcher payload variants contain build names (with some differing from each other) . The launcher payload passes the build name as the \u201c-b\u201d argument when executing the BoryptGrab stealer it downloads. As an example, the build name shown in the following figure is \u201c<i>Shrek<\/i>\u201d.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"764952\" data-modal-title=\"Figure 8. The launcher payload sends the build name argument to the downloaded BoryptGrab stealer\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig8.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig8.png\" alt=\"Figure 8. The launcher payload sends the build name argument to the downloaded BoryptGrab stealer\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 8. The launcher payload sends the build name argument to the downloaded BoryptGrab stealer<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>The launcher variants can send requests with a hardcoded build name to download other files (<i>:5466\/api\/custom_exe?build={BUILD_NAME}<\/i>). These files are variants of the Vidar stealer (as discussed in later sections).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"a89ec4\" data-modal-title=\"Figure 9. Traffic from launcher to download Vidar stealer\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig9.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig8.png\" alt=\"Figure 9. Traffic from launcher to download Vidar stealer\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 9. Traffic from launcher to download Vidar stealer<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"34\">\n<div readability=\"13\">\n<p>Several build names have been observed in the wild for the \u201c<i>\/api\/custom_exe?build={BUILD_NAME}<\/i>\u201drequests to download Vidar variants:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">CryptoByte<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Kassay<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Leon<\/span><\/li>\n<li><span class=\"rte-red-bullet\">NeoWho<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Shrek<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Sonic<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Yaropolk<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Yarostnick<\/span><\/li>\n<\/ul>\n<p>The launcher payload also downloads a Pyinstaller executable from the attacker\u2019s server (:5466\/api\/client) which we named TunnesshClient. The launcher payload schedules tasks that use .xml files at <i>%TEMP%\\client_task_system.xml<\/i> and <i>%TEMP%\\client_task_user.xml<\/i> to execute the downloaded TunnesshClient.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <a id=\"b1e2f1\" data-modal-title=\"Figure 10. The launcher creates a scheduled task for the downloaded TunnesshClient\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig10.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig10.png\" alt=\"Figure 10. The launcher creates a scheduled task for the downloaded TunnesshClient\"> <\/a> <\/p>\n<p><figcaption>Figure 10. The launcher creates a scheduled task for the downloaded TunnesshClient<\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The launcher payload can also download an executable <b>\u2014<\/b> a binary written in Golang (which we dubbed as HeaconLoad) from \u201c<i>:5466\/api\/lodik<\/i>\u201d. . It further downloads and runs another executable.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"2d0e14\" data-modal-title=\"Figure 11. Traffic from the launcher to download HeaconLoad\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig11.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig11.png\" alt=\"Figure 11. Traffic from the launcher to download HeaconLoad\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 11. Traffic from the launcher to download HeaconLoad<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"36\">\n<div readability=\"17\">\n<p>Some ZIP file variants can contain a VBS downloader that further delivers other malware. We used one VBS downloader script containing unused variables as junk code for obfuscation (SHA256: 1bd605ef84b6767df74bd6290f1468eed5a88264df23fcf70b6a75d5bdcf7d76) for demonstration.<\/p>\n<p>The VBS script uses integer arrays to represent strings. It contains a function &#8220;A&#8221; that converts integer arrays to their corresponding strings. The script also includes a function named <i>EnsureElevatedPrivileges<\/i> for privilege escalation.<\/p>\n<p>The strings converted from integer arrays are encoded PowerShell payloads. The final decoded command in the VBS script downloads and Base64-decodes a binary executable from <u>hxxps:\/\/botshield[.]vu\/kFcjld<\/u>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"f67c52\" data-modal-title=\"Figure 12. VBS downloader downloads and executes file from attacker\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig12.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig12.png\" alt=\"Figure 12. VBS downloader downloads and executes file from attacker\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 12. VBS downloader downloads and executes file from attacker<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The inal deobfuscated commands in the VBS script can also set Microsoft Defender exclusions to prevent the <i>C:\\<\/i> drive from performing anti-virus scanning.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"cb99ac\" data-modal-title=\"Figure 13. The VBS downloader configures exclusion path for Windows Defender\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig13.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig13.png\" alt=\"Figure 13. The VBS downloader configures exclusion path for Windows Defender\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 13. The VBS downloader configures exclusion path for Windows Defender<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>The file downloaded and decoded by the VBS script is a C\/C++ launcher binary that further downloads the BoryptGrab stealer by sending an HTTP request (<i>\/api\/{BUILD_NAME}<\/i>) with a build name. The following image shows the HTTP request from a C\/C++ launcher variant (SHA256:15de71073f44c657c23f5f97caa11f1b12e654d4d17684bfc628cc1e5b6bcdd5) with the build name \u201cCryptoByte\u201d. Different build names have also been observed for different launcher variants. These build names correspond to the build name values hardcoded in the BoryptGrab samples as described in later sections.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <a id=\"695d82\" data-modal-title=\"Figure 14. Traffic from the launcher binary to download the BoryptGrab stealer\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig14.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig14.png\" alt=\"Figure 14. Traffic from the launcher binary to download the BoryptGrab stealer\"> <\/a> <\/p>\n<p><figcaption>Figure 14. Traffic from the launcher binary to download the BoryptGrab stealer<\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"36\">\n<div readability=\"17\">\n<p>In this attack chain, variants of the downloaded BoryptGrab (SHA256: 4e90d386c1c7d3d1fd4176975795a2f432d95685690778e09313b4a1dbab9997) can download TunnesshClient themselves rather than letting the launcher binary download it.<\/p>\n<p>In some variants, a .NET executable (SHA256: 4264a88035aa0b63e9aef96daa78a58114d60a344ea10168a8ef5ef36bf8edbd) is used to decode and run a Base64-encoded VBS downloader (SHA256: 433a13cc70396f80dc29d1150c050339d78964fdc91bcdc3f40c67a77add1476). In the sample we analyzed, the VBS downloader downloads and executes a binary executable from \u201c<i><u>hxxps:\/\/botshield[.]vu\/KKRkm9<\/u><\/i>\u201d.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <a id=\"bbf6e1\" data-modal-title=\"Figure 15. The .NET binary embeds a Base64-encoded VBS downloader\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig15.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig15.png\" alt=\"Figure 15. The .NET binary embeds a Base64-encoded VBS downloader\"> <\/a> <\/p>\n<p><figcaption>Figure 15. The .NET binary embeds a Base64-encoded VBS downloader<\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"36.5\">\n<div readability=\"18\">\n<p>Variants of the launcher (SHA256: 7f2315b89fb9a47e1516def136844d617bfcdce19000a1b0436706692dbe166c) can download files from \u201c<i>:5466\/api\/app<\/i>\u201d or \u201c<i>:5466\/api\/app.zip<\/i>\u201d depending on its privilege. Meanwhile, another launcher variant (SHA256: 449f528f5ceae8c3f8336d0d8e3e3ec9031d1ad67c31ee7311b67e01d5fdf225) can also download the payload from \u201c<i>:5466\/api\/payload<\/i>\u201d. A third variant we analyzed (SHA256: c40b9913e79c5dd09751b1afb03aaa98658bab61bacf27a299abd84fd44fe707) can also download TunnesshClient at \u201c<i>:5466\/api\/client2<\/i>\u201d.<\/p>\n<p>Meanwhile, some Some zip file variants can directly contain the HeaconLoad downloader to deliver malware.<\/p>\n<p>The HeaconLoad sample (SHA256: 2abe0ef88ba92db79d82cde4c0ed1f382bb347517a54ea82084c841d0f955518) achieves persistence by adding a registry entry under the <i>Run<\/i> key and creating a scheduled task.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"3d2463\" data-modal-title=\"Figure 16. HeaconLoad achieves persistence\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig16.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig16.png\" alt=\"Figure 16. HeaconLoad achieves persistence\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 16. HeaconLoad achieves persistence<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>HeaconLoad sends beacon messages to the attacker via HTTP POST requests at \u201c<i>:8088\/healthcheck<\/i>\u201d. Each beacon message contains collected system information along with a build tag value hardcoded in the HeaconLoad sample.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"cd9afe\" data-modal-title=\"Figure 17. HeaconLoad sends a beacon message with build tag \u201cyaropolk\u201d to check for status of the bundle to download\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig17.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig17.png\" alt=\"Figure 17. HeaconLoad sends a beacon message with build tag \u201cyaropolk\u201d to check for status of the bundle to download\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 17. HeaconLoad sends a beacon message with build tag \u201cyaropolk\u201d to check for status of the bundle to download<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>The following are different hardcoded build tag values we have observed from HeaconLoad variants:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">kylka<\/span><\/li>\n<li><span class=\"rte-red-bullet\">leon<\/span><\/li>\n<li><span class=\"rte-red-bullet\">shrek<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sonic<\/span><\/li>\n<li><span class=\"rte-red-bullet\">voblya<\/span><\/li>\n<li><span class=\"rte-red-bullet\">yaropolk<\/span><\/li>\n<li><span class=\"rte-red-bullet\">yarostnick<\/span><\/li>\n<li><span class=\"rte-red-bullet\">yasno<\/span><\/li>\n<\/ul>\n<p>HeaconLoad then checks fields such as \u201c<i>bundle_available<\/i>\u201d and \u201c<i>bundle_hash<\/i>\u201d in the attacker\u2019s response to its HTTP POST request. These two fields respectively indicate whether a bundle is available for download and provide the hash value of the bundle to download for verification.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <a id=\"aab0ee\" data-modal-title=\"Figure 18. HeaconLoad checks the \u201cbundle_available\u201d field from attacker\u2019s response\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig18.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig18.png\" alt=\"Figure 18. HeaconLoad checks the \u201cbundle_available\u201d field from attacker\u2019s response\"> <\/a> <\/p>\n<p><figcaption>Figure 18. HeaconLoad checks the \u201cbundle_available\u201d field from attacker\u2019s response<\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>When a bundle is available, HeaconLoad further downloads and unzips a bundle archive from the attacker\u2019s server. It executes the first executable found in the unzipped archive.<\/p>\n<p>We observed Russian log messages in HeaconLoad samples.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"392186\" data-modal-title=\"Figure 19. Russian-language log message in HeaconLoad (translated as \u201cdata marshaling error\u201d)\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig19.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig19.png\" alt=\"Figure 19. Russian-language log message in HeaconLoad (translated as \u201cdata marshaling error\u201d)\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 19. Russian-language log message in HeaconLoad (translated as \u201cdata marshaling error\u201d)<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>The binary executables downloaded from \u201c<i>\/api\/custom_exe?build={BUILD_NAME}<\/i>\u201d are variants of the existing Vidar stealer with code obfuscation.<\/p>\n<p>The sample (SHA256: 2050468744e44554fac17fb83f1515c95f2f2236716e2b5267a81c2b94205e6a) possesses a functionality that sends HTTP POST requests with traffic patterns used by the Vidar stealer. It uses XOR-encrypted strings and contains opaque predicates with redundant code for obfuscation.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"96f51c\" data-modal-title=\"Figure 20. Vidar variant sends information.txt to the attacker via POST request\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig20.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig20.png\" alt=\"Figure 20. Vidar variant sends information.txt to the attacker via POST request\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 20. Vidar variant sends information.txt to the attacker via POST request<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p>The Vidar variant also dynamically resolves its API for obfuscation and can also perform code injection or APC injection.<\/p>\n<p>BoryptGrab takes an optional &#8220;&#8211;output-path&#8221;\/&#8221;-o&#8221; argument that specifies the output directory to hold data it collects.&nbsp; Depends on the build, some variants of BoryptGrab (SHA256: fe4e5fb28d2c2b3a640112b6b125ce8c4afa8be28342e3bfda097ad9dd2ef9ee) also take an optional \u201c&#8211;build-name\u201d\/\u201c-b\u201d command line argument as input. This input argument is used as the value of the \u201c<i>BUILD NAME<\/i>\u201d field when BoryptGrab outputs user information to the <i>UserInformation.txt<\/i> file. When no \u201c&#8211;build-name\u201d argument is provided, the BoryptGrab variant uses the default build name \u201cNO_NAME\u201d.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"a8cf3d\" data-modal-title=\"Figure 21. Arguments parsed by BoryptGrab\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig21.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig21.png\" alt=\"Figure 21. Arguments parsed by BoryptGrab\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 21. Arguments parsed by BoryptGrab<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>Meanwhile, some variants of BoryptGrab use hardcoded values for the \u201cBUILD NAME\u201d field in <i>UserInformation.txt<\/i> instead of parsing the \u201c&#8211;build-name\u201d\/\u201c-b\u201d argument.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <a id=\"0889cd\" data-modal-title=\"Figure 22. Hardcoded build name \u201cCryptoByte\u201d in BoryptGrab\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig22.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig22.png\" alt=\"Figure 22. Hardcoded build name \u201cCryptoByte\u201d in BoryptGrab\"> <\/a> <\/p>\n<p><figcaption>Figure 22. Hardcoded build name \u201cCryptoByte\u201d in BoryptGrab<\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"48.5\">\n<div readability=\"42\">\n<p>Note that there are also BoryptGrab variants that do not contain hardcoded the \u201cBUILD NAME\u201d and do not parse the \u201c&#8211;build-name\u201d\/\u201c-b\u201d. command line argument. They also do not write the \u201cBUILD NAME\u201d field to the <i>UserInformation.txt<\/i> file.<\/p>\n<p>The following shows a list of build name values hardcoded in the BoryptGrab variants we have observed in the wild:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">CryptoByte<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Crypto_Byte<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Data<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Kassay<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Leon<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Pisechka<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Shrek<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Sonic<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Sonic2<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Sonic_new1<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Sonic_new2<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Yaropolk<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&nbsp;Yarostnick<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Yasno<\/span><\/li>\n<li><span class=\"rte-red-bullet\">bigdick<\/span><\/li>\n<li><span class=\"rte-red-bullet\">wm_detect<\/span><\/li>\n<\/ul>\n<p>BoryptGrab detects whether it is executed in a virtual machine environment by querying registry entries and checking VM-related files.<\/p>\n<p>As part of its anti-analysis check, BoryptGrab also compares the names of running processes against a predefined list. It also attempts to execute with elevated privilege.<\/p>\n<p>When the &#8220;&#8211;output-path&#8221;\/&#8221;-o&#8221; argument is not given, BoryptGrab formats a default output path name using the current time, public IP address, and country code. Later, a directory with this output path name is created to stage collected data.<\/p>\n<p>BoryptGrab collects information from a list of browsers. It uses Chrome App Bound Encryption techniques and contains code from the following public GitHub repositories:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">https:\/\/github[.]com\/00nx\/Chrome-App-Bound-Encryption-Bypass<\/span><\/li>\n<li><span class=\"rte-red-bullet\">https:\/\/github[.]com\/xaitax\/Chrome-App-Bound-Encryption-Decryption<\/span><\/li>\n<\/ul>\n<p>The following are the list of browsers BoryptGrab collects information from:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Brave Browser<\/span><\/li>\n<li><span class=\"rte-red-bullet\">CentBrowser<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Chromium<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Google Chrome<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Microsoft Edge<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Mozilla Firefox<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Opera<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Vivaldi<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Yandex Browser<\/span><\/li>\n<\/ul>\n<p>BoryptGrab uses code similar to the loadAndDecryptPayload function in https:\/\/github[.]com\/00nx\/Chrome-App-Bound-Encryption-Bypass, while also containing a binary with an encrypted resource named \u201cPAYLOAD_DLL\u201d, as used by the GitHub repository.<\/p>\n<p>The decrypted PAYLOAD_DLL resource in BoryptGrab contains logic from the Chrome-App-Bound-Encryption-Bypass public Github repository. The decrypted resource payload in BoryptGrab also contains functionality that collects browser data from Yandex and Firefox.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"1e9b90\" data-modal-title=\"Figure 23. PAYLOAD_DLL payload in BoryptGrab collects passwords from the Yandex browser\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig23.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig23.png\" alt=\"Figure 23. PAYLOAD_DLL payload in BoryptGrab collects passwords from the Yandex browser\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 23. PAYLOAD_DLL payload in BoryptGrab collects passwords from the Yandex browser<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The decrypted PAYLOAD_DLL payload also contains hardcoded timestamp information. It writes the timestamp along with installed application information to the \u201c<i>installed_applications.txt<\/i>\u201d file.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"7ad673\" data-modal-title=\"Figure 24. The PAYLOAD_DLL payload writes the hardcoded timestamp along with the installed applications\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig23.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig24.png\" alt=\"Figure 24. The PAYLOAD_DLL payload writes the hardcoded timestamp along with the installed applications\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 24. The PAYLOAD_DLL payload writes the hardcoded timestamp along with the installed applications<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p>To help collect browser data, BoryptGrab downloads a Chromium helper (SHA256: ed1745cc49b929e499966d87e163219fe0f24069fe88dfacbd69c0ebab85a640) from \u201c<i>hxxp:\/\/45.93.20[.]61:5466\/api\/x32_chromium<\/i>\u201d<i> <\/i>and saves it to <i>%TEMP%\\ x32_chromium.exe<\/i>.<\/p>\n<p>Aside from browser data, BoryptGrab can harvest information from both desktop cryptocurrency wallet applications and browser extensions. BoryptGrab then captures a screenshot and collects system information.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"6eebee\" data-modal-title=\"Figure 25. Log messages for cryptocurrency wallet information in BoryptGrab\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig25.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig25.png\" alt=\"Figure 25. Log messages for cryptocurrency wallet information in BoryptGrab\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 25. Log messages for cryptocurrency wallet information in BoryptGrab<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>The following cryptocurrency wallet directories are targeted by BoryptGrab:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Armory Wallet<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Atomic<\/span><\/li>\n<li><span class=\"rte-red-bullet\">AtomicDEX<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Binance<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Bitcoin Core<\/span><\/li>\n<li><span class=\"rte-red-bullet\">BitPay<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Blockstream Green<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Chia Wallet<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Coinomi<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Copay<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Daedalus Mainnet<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Dash Core<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Dogecoin<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Electron Cash<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Electrum<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ElectrumLTC<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Ethereum<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Exodus<\/span><\/li>\n<li><span class=\"rte-red-bullet\">GreenAddress<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Guarda<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Jaxx Desktop<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Komodo Wallet<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Ledger Live<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Ledger Wallet<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Litecoin Core<\/span><\/li>\n<li><span class=\"rte-red-bullet\">MEW Desktop<\/span><\/li>\n<li><span class=\"rte-red-bullet\">MultiDoge<\/span><\/li>\n<li><span class=\"rte-red-bullet\">MyEtherWallet<\/span><\/li>\n<li><span class=\"rte-red-bullet\">NOW Wallet<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Raven Core<\/span><\/li>\n<li><span class=\"rte-red-bullet\">StakeCube<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Trezor Suite<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Wasabi Wallet<\/span><\/li>\n<\/ul>\n<p>BoryptGrab also contains a \u201cFile Grabber\u201d ability, where it collects files with specified extensions under common directories. It contains a misspelled word: \u201cFilegraber\u201d.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <a id=\"61d6bc\" data-modal-title=\"Figure 26. Examples of file extensions harvested by BoryptGrab\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig26.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig26.png\" alt=\"Figure 26. Examples of file extensions harvested by BoryptGrab\"> <\/a> <\/p>\n<p><figcaption>Figure 26. Examples of file extensions harvested by BoryptGrab<\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"38\">\n<div readability=\"21\">\n<p>Finally, BoryptGrab collects Telegram files and browser passwords, with newer variants of BoryptGrab being able to gather Discord tokens.<\/p>\n<p>After data collection, BoryptGrab archives and uploads its collected data to the attacker\u2019s server.<\/p>\n<p>Some BoryptGrab variants download and execute TunnesshClient from the attacker\u2019s server. However, not all BoryptGrab variants have this functionality, and in some attack chains, TunnesshClient is delivered by other downloaders instead.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"0ecee3\" data-modal-title=\"Figure 27. Traffic from BoryptGrab variant to download TunnesshClient\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig27.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig27.png\" alt=\"Figure 27. Traffic from BoryptGrab variant to download TunnesshClient\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 27. Traffic from BoryptGrab variant to download TunnesshClient<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"36\">\n<div readability=\"17\">\n<p>TunnesshClient is a PyInstaller executable that conducts traffic forwarding and executes the attacker\u2019s commands through a reverse SSH tunnel. It contains Russian text in its comments and log messages, indicating possible origins. The TunnesshClient sample used in this blog for demonstration (SHA256: 576692df4bf1c7d8927d3a183f5219a81c3bff3dd22971691f8af6889f80c5a0) connects to the attacker\u2019s server at 193.143.1[.]104.<\/p>\n<p>TunnesshClient first retrieves SSH credentials by sending HTTP POST requests (<i>\/api\/get_challenge<\/i>, <i>\/api\/get_credentials<\/i>) to hxxp:\/\/193.143.1[.]104:5000. It solves the attacker\u2019s challenge by computing a SHA256 hash to retrieve an encrypted response. It then decrypts the response to obtain SSH credentials in JSON format.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"ef4c6c\" data-modal-title=\"Figure 28. TunnesshClient sends HTTP POST requests to retrieves SSH credentials from the attacker\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig28.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig28.png\" alt=\"Figure 28. TunnesshClient sends HTTP POST requests to retrieves SSH credentials from the attacker\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 28. TunnesshClient sends HTTP POST requests to retrieves SSH credentials from the attacker<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p>TunnesshClient then sends system information to the attacker at \u201c<i>\/api\/get_port<\/i>\u201d. It retrieves a port number for remote port forwarding from the attacker\u2019s response, then creates a reverse SSH tunnel using its previously retrieved SSH credentials and traffic-forwarding port number to communicate with the attacker\u2019s server.<\/p>\n<p>TunnesshClient can execute commands provided by the attacker. It receives an integer value from the attacker\u2019s connection, which represents the operation type of the command to execute.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"08601e\" data-modal-title=\"Figure 29. Operation types parsed by TunnesshClient variant\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig29.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/Fig29.png\" alt=\"Figure 29. Operation types parsed by TunnesshClient variant\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 29. Operation types parsed by TunnesshClient variant<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The following table lists the operation types supported by the TunnesshClient sample and their corresponding commands:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\">\n<div class=\"responsive-table-wrap\">\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\" width=\"100%\" height=\"10%\">\n<tbody readability=\"4\">\n<tr>\n<th scope=\"col\"><b>Operation type<\/b><\/th>\n<th scope=\"col\"><b>Description<\/b><\/th>\n<\/tr>\n<tr>\n<td height=\"23\" width=\"283\">5<\/td>\n<td width=\"283\">Act as SOCKS5 proxy<\/td>\n<\/tr>\n<tr>\n<td height=\"23\" width=\"283\">83<\/td>\n<td width=\"283\">Execute shell command<\/td>\n<\/tr>\n<tr>\n<td height=\"23\" width=\"283\">76<\/td>\n<td width=\"283\">List specified files<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td height=\"23\" width=\"283\">68<\/td>\n<td width=\"283\">Send victim\u2019s file to attacker in base64 encoding<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td height=\"23\" width=\"283\">85<\/td>\n<td width=\"283\">Save Base64-encoded file content from attacker to victim\u2019s machine<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td height=\"23\" width=\"283\">70<\/td>\n<td width=\"283\">Search for file with specified query<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td height=\"23\" width=\"283\">90<\/td>\n<td width=\"283\">Send victim\u2019s folder to the attacker in a Base64-encoded ZIP archive<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p><sup>Table 1. Operation types supported by the TunnesshClient sample and their corresponding commands<\/sup><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p>Another variant of TunnesshClient (SHA256: 0434437a073a3f3a49e84d5ecb20c99dd551bacc32bf100fbb8cf67a50642181) sets up a local SSH server on the victim machine. It sends the username and password for local SSH connection to the attacker through an HTTP POST request (hxxp:\/\/45.93.20[.]195:5000).<\/p>\n<p>When the operation type is 83, this TunnesshClient variant forwards the attacker\u2019s traffic to the local SSH server. This variant only accepts operation type 5 and 83, and does not execute the attacker\u2019s commands as the previous variant does.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\">\n<div class=\"responsive-table-wrap\">\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\" width=\"100%\" height=\"10%\">\n<tbody>\n<tr>\n<th scope=\"col\">Operation type<\/th>\n<th scope=\"col\">Description<\/th>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>Act as SOCKS5 proxy<\/td>\n<\/tr>\n<tr>\n<td>83 or other values<\/td>\n<td>Local SSH forwarding<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"44.252771084337\">\n<div readability=\"41.245301204819\">\n<p>The BoryptGrab campaign illustrates an evolving threat ecosystem targeting users through deceptive software downloads and fake GitHub repositories. Across its many variants, the stealer demonstrates extensive data\u2011harvesting capabilities, with its ability to dynamically stage payloads, bypass analysis through anti\u2011VM and anti\u2011debug checks and offload sensitive operations to encrypted payloads showing a level of engineering sophistication that continues to increase.<\/p>\n<p>The campaign\u2019s reliance on SEO\u2011optimized GitHub repositories and fake \u201cfree tool\u201d download sites underscores an important trend: threat actors increasingly exploit trust in legitimate developer platforms and open\u2011source ecosystems. With dozens of repositories, shifting payloads, and numerous build names observed in the wild, the operation\u2019s scale indicates an active and ongoing threat.<\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/one-platform.html\">TrendAI&nbsp;Vision One\u2122<\/a>&nbsp;is the industry-leading AI cybersecurity platform that centralizes cyber risk exposure management, security operations, and robust layered protection.<\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/threat-intelligence.html\">TrendAI Vision One\u2122 Threat Intelligence Hub<\/a>&nbsp;provides&nbsp;the latest insights on emerging threats and threat actors, exclusive strategic reports from&nbsp;TrendAI\u2122 Research, and&nbsp;TrendAI&nbsp;Vision One\u2122&nbsp;Threat Intelligence Feed in the&nbsp;TrendAI&nbsp;Vision One\u2122&nbsp;platform.&nbsp;<\/p>\n<p>Emerging Threats:&nbsp;<a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence_insights?name=From%20Fake%20GitHub%20Download%20Repositories%20to%20Reverse%20SSH%20Backdoors%3A%20Examining%20the%20BoryptGrab%20Stealer\" title=\"From Fake GitHub Download Repositories to Reverse SSH Backdoors: Examining the BoryptGrab Stealer\">From Fake GitHub Download Repositories to Reverse SSH Backdoors: Examining the BoryptGrab Stealer<\/a><\/p>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p><a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence?intrusionSet=From%20Fake%20GitHub%20Download%20Repositories%20to%20Reverse%20SSH%20Backdoors%3A%20Examining%20the%20BoryptGrab%20Stealer\">From Fake GitHub Download Repositories to Reverse SSH Backdoors: Examining the BoryptGrab Stealer<\/a> &nbsp;<\/p>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>TrendAI&nbsp;Vision One\u2122&nbsp;customers can use the Search App to match or hunt the malicious indicators mentioned in this blog post with data in their environment.\u202f\u202f\u202f\u202f&nbsp;<\/p>\n<p><b>Detection of BORYPTGRAB samples<\/b><\/p>\n<p>malName: *BORYPTGRAB* AND eventName: MALWARE_DETECTION AND LogType: detection<\/p>\n<p>More hunting queries are available for&nbsp;TrendAI&nbsp;Vision One\u2122&nbsp;<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/threat-intelligence.html\">with\u202fThreat&nbsp;Intelligence Hub<\/a>&nbsp;entitlement enabled.\u202f&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"29.68085106383\">\n<div readability=\"6.7021276595745\">\n<p>The indicators of compromise for this entry can be found <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/c\/boryptgrab\/IOCs_BoryptGrab_Stealer.txt\"><span class=\"bs-modal\">here<\/span><\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/c\/boryptgrab-stealer-targets-users-via-deceptive-github-pages.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The BoryptGrab campaign uses fake SEO\u2011optimized GitHub repositories and deceptive download pages to distribute a data\u2011stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9511,9513,9509],"class_list":["post-60264","post","type-post","status-publish","format-standard","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cyber-threats","tag-trend-micro-research-malware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-05T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/AsyncRAT-cover:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"18 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages\",\"datePublished\":\"2026-03-05T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/\"},\"wordCount\":3530,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/AsyncRAT-cover:Large?qlt=80\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cyber Threats\",\"Trend Micro Research : Malware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/\",\"name\":\"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/AsyncRAT-cover:Large?qlt=80\",\"datePublished\":\"2026-03-05T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/AsyncRAT-cover:Large?qlt=80\",\"contentUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/AsyncRAT-cover:Large?qlt=80\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/","og_locale":"en_US","og_type":"article","og_title":"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-03-05T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/AsyncRAT-cover:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"18 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages","datePublished":"2026-03-05T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/"},"wordCount":3530,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/#primaryimage"},"thumbnailUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/AsyncRAT-cover:Large?qlt=80","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cyber Threats","Trend Micro Research : Malware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/","url":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/","name":"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/#primaryimage"},"thumbnailUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/AsyncRAT-cover:Large?qlt=80","datePublished":"2026-03-05T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/#primaryimage","url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/AsyncRAT-cover:Large?qlt=80","contentUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/AsyncRAT-cover:Large?qlt=80"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60264","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=60264"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60264\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=60264"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=60264"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=60264"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}