← Back to Feed
New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages
March 5, 2026 · Trend Micro · Severity: HIGH
The BoryptGrab campaign uses fake SEO‑optimized GitHub repositories and deceptive download pages to distribute a data‑stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.
Key Takeaways
- The BoryptGrab campaign uses fake SEO‑optimized GitHub repositories and deceptive download pages to distribute a.
- The BoryptGrab campaign uses fake SEO‑optimized GitHub repositories and deceptive download pages to distribute a data‑stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.