BoryptGrab GitHub Supply Chain Malware Campaign — 100+ Malicious Repositories Distributing Multi-Stage Stealer — Threadlinqs Intelligence
As of 2026-05-30, BoryptGrab GitHub Supply Chain Malware Campaign — 100+ Malicious Repositories Distributing Multi-Stage Stealer is a high-severity malware threat attributed to a Russia-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-0207 · Severity: HIGH · CVSS: 7.5 · Status: MONITORING · Category: MALWARE
Attribution: Russia · FINANCIAL
A large-scale supply chain attack distributing the BoryptGrab information stealer through over 100 malicious GitHub repositories. Russian-origin threat actors create SEO-optimized fake open-source
The BoryptGrab campaign represents a sophisticated supply chain attack leveraging GitHub's trusted reputation to distribute information-stealing malware at scale. Discovered by Trend Micro and publicly disclosed on March 5, 2026, the campaign operates through over 100 malicious GitHub repositories that impersonate legitimate software tools, game cheats, and developer utilities.
The attack chain begins with SEO-optimized GitHub repositories containing README files with search-engine-targeted keywords. Victims are directed through encoded URL redirect chains to fake download pages hosted on GitHub Pages (e.g., voicemod-pro-download-tool.github.io) or attacker-controlled domains (best-tinted.com). The downloaded ZIP archives contain the initial payload.
Four distinct attack routes have been identified:
1. DLL Side-Loading: Executable side-loads a malicious libcurl.dll which XOR+AES-CBC decrypts a launcher from its resource section. The launcher calls an _EntryWrapper_ export function and contacts the C2 at 45.93.20.61:5466 to retrieve payloads.
2. VBS Downloader Chain: Obfuscated VBS scripts with integer array encoding attempt UAC bypass via EnsureElevatedPrivileges, disable Windows Defender by excluding C:\ from scanning via PowerShell, then download binaries from botshield.vu.
3. .NET Embedded VBS: A .NET executable decodes a Base64-embedded VBS downloader that continues the infection chain.
4. Direct HeaconLoad: A Golang downloader establishes persistence via registry Run keys and scheduled tasks, beacons to port 8088, and downloads/executes ZIP bundles.
The primary payload, BoryptGrab, is a C/C++ stealer that bypasses Chrome App Bound Encryption (incorporating code from public GitHub repositories), harvests credentials from 9+ browsers (Chrome, Edge, Firefox, Opera, Brave, Vivaldi, Yandex, CentBrowser, Chromium), steals cryptocurrency wallet files from 30+ wallets (Exodus, Electrum, Ledger, Trezor, Atomic, Binance, Bitcoin Core, Ethereum, and others), extracts Telegram files and Discord tokens, captures screenshots, and performs file grabbing from common directories.
TunnesshClient is a PyInstaller-based reverse SSH backdoor that retrieves encrypted SSH credentials from 193.143.1.104:5000 via a challenge-response mechanism. It supports SOCKS5 proxying (op 5), shell command execution (op 83), file listing (op 76), file exfiltration (op 68), file writing (op 85), file search (op 70), and folder exfiltration as Base64-encoded ZIPs (op 90).
HeaconLoad is a Golang downloader that establishes persistence through registry Run keys and scheduled tasks, beacons to the C2 at port 8088 with system information and build tags, and downloads ZIP bundles for execution.
Build names are used to track infection campaigns: Shrek, Leon, CryptoByte, Sonic, Yaropolk, Yarostnick, Yasno, Kassay, Pisechka, and others. Russian-language comments in source code, Russian variable names, Russian-located C2 infrastructure, and Slavic build names strongly indicate Russian-origin operators.
The campaign has been active since at least April 2025 (earliest repository commits) with malicious ZIPs identified in late 2025. The scale of 100+ repositories with active SEO optimization represents significant operational investment and ongoing threat to the software supply chain.
---
**Revalidated on 2026-03-12**
Revalidation (2026-03-12): The campaign remains confirmed active with no C2 infrastructure takedowns reported. Repository rotation by operators continues -- when repositories are flagged or removed by GitHub, new ones are rapidly created with modified names and descriptions to maintain search engine presence. PCRisk has published end-user removal instructions, confirming infections have reached consumers beyond the initial developer/gamer target audience. The broader 2026 GitHub supply chain threat landscape is intensifying: the Shai-Hulud 2.0 worm campaign exposed 33,185 secrets across 20,649 repositories, UNC6426 exploited the nx npm supply ch
Weaknesses (CWE)
CWE-506, CWE-494, CWE-829
Target sectors: technology, software-development, gaming, cryptocurrency, financial
Target regions: Global
Detections & IOCs
As of 2026-07-21, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.001, T1195.002, T1059.005, T1059.001, T1204.002, T1547.001, T1053.005, T1548.002, T1027, T1027.013