← Back to Feed

New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages

March 5, 2026 · Trend Micro · Severity: HIGH

The BoryptGrab campaign uses fake SEO‑optimized GitHub repositories and deceptive download pages to distribute a data‑stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.

Key Takeaways

  • The BoryptGrab campaign uses fake SEO‑optimized GitHub repositories and deceptive download pages to distribute a.
  • The BoryptGrab campaign uses fake SEO‑optimized GitHub repositories and deceptive download pages to distribute a data‑stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.
☕ Buy a Coffee