Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
BoryptGrab Malware Targets Users via Fake GitHub Projects

BoryptGrab Malware Targets Users via Fake GitHub Projects

Posted on March 9, 2026 By CWS

A newly identified malware known as BoryptGrab is rapidly spreading across Windows platforms. It utilizes fake GitHub repositories to deceive users into downloading what seem to be popular free software tools.

How BoryptGrab Operates

The campaign, active since April 2025, cleverly manipulates search engines to present these malicious repositories as legitimate, leading users into an intricate infection chain. This process ultimately results in the theft of sensitive information, which is covertly sent to the attackers.

A significant number of GitHub repositories have been established by the threat actors, each posing as a download page for various tools, including game cheats and productivity applications. These repositories use SEO-optimized keywords to rank highly in search results, appearing alongside authentic results.

Uncovering the Infection Chain

Upon clicking download links in these repositories, users undergo multiple redirections, involving base64-encoded and AES-encrypted URLs, before landing on a deceptive download page that distributes a malicious ZIP file. Trend Micro analysts traced the BoryptGrab campaign while investigating suspicious ZIP files, linking the infection chain back to these GitHub-hosted pages.

The research revealed a complex operation involving various payload variants, tagged with build names like “Shrek” and “CryptoByte.” This indicates a well-organized and ongoing threat. BoryptGrab is capable of extracting credentials and cookies from popular browsers like Chrome and Firefox, and targets over 30 cryptocurrency wallet applications, including Exodus and Ledger Live.

Potential Threats and Precautions

A notable aspect of this campaign is the inclusion of TunnesshClient, a backdoor that establishes a reverse SSH tunnel to the attacker’s server, allowing remote command execution and file transfer. Russian-language comments in the code and IP addresses linked to Russia suggest the origin of the attackers.

The infection starts when a victim downloads a ZIP file from these fake GitHub pages, leading to a page that redirects and serves a malicious ZIP file based on the victim’s visit. The payload within the ZIP can take various forms, including executables that decrypt embedded payloads or VBS scripts that use obfuscated PowerShell commands.

To minimize risk, users should download software only from verified sources and avoid free tools from unfamiliar GitHub repositories. Security teams should monitor for suspicious activities such as unexpected scheduled tasks and unusual outbound traffic. Keeping security tools up-to-date and verifying software sources are vital steps in reducing exposure to such threats.

Stay updated with the latest cybersecurity news by following us on Google News, LinkedIn, and X. Set CSN as your go-to source on Google for instant updates.

Cyber Security News Tags:BoryptGrab, browser security, crypto wallets, Cybersecurity, data protection, data theft, GitHub, Malware, Russian hackers, Trend Micro

Post navigation

Previous Post: Fake CleanMyMac Site Targets Users with SHub Stealer
Next Post: VIP Keylogger Campaign Threatens Cybersecurity

Related Posts

Critical SolarWinds Vulnerability Demands Immediate Action Critical SolarWinds Vulnerability Demands Immediate Action Cyber Security News
Critical Plesk Flaw Allows Command Execution on Servers Critical Plesk Flaw Allows Command Execution on Servers Cyber Security News
Hackers Exploiting Blind Spots in DNS Records to Store and Deliver Malware Hackers Exploiting Blind Spots in DNS Records to Store and Deliver Malware Cyber Security News
Dark Web Job Market Evolved Dark Web Job Market Evolved Cyber Security News
Ransomware Actors Primarily Targeting Retailers This Holiday Season to Deploy Malicious Payloads Ransomware Actors Primarily Targeting Retailers This Holiday Season to Deploy Malicious Payloads Cyber Security News
Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Optimize SOC Efficiency with Threat Intelligence Feeds
  • Critical Flaw in Veeam Poses RCE Threat to Servers
  • Microsoft Fixes 200 Flaws in June Patch Tuesday
  • Critical Veeam Vulnerability Enables Remote Code Execution
  • Microsoft’s June 2026 Update Fixes 198 Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Optimize SOC Efficiency with Threat Intelligence Feeds
  • Critical Flaw in Veeam Poses RCE Threat to Servers
  • Microsoft Fixes 200 Flaws in June Patch Tuesday
  • Critical Veeam Vulnerability Enables Remote Code Execution
  • Microsoft’s June 2026 Update Fixes 198 Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark