← Back to Feed
New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages
March 5, 2026 · Trend Micro · Severity: HIGH
The BoryptGrab campaign uses fake SEO‑optimized GitHub repositories and deceptive download pages to distribute a data‑stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.
Key Takeaways
- The BoryptGrab campaign uses fake SEO-optimized GitHub repositories and deceptive download pages.
- The malware distributes a data-stealing family with multiple payloads, including a reverse SSH backdoor.
- The campaign targets Windows users through fake GitHub pages.