← Back to Feed
New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages
March 5, 2026 · Trend Micro · Severity: HIGH
The BoryptGrab campaign uses fake SEO‑optimized GitHub repositories and deceptive download pages to distribute a data‑stealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.
Key Takeaways
- The BoryptGrab campaign uses fake SEO-optimized GitHub repositories and deceptive download pages to distribute data-stealing malware to Windows users.
- Victims receive multiple payloads, including a reverse SSH backdoor, after downloading booby-trapped tools from deceptive GitHub Pages sites.
- Windows users should avoid downloading software from unofficial GitHub Pages links and verify repository authenticity before running files.