Malware
BoryptGrab
According to Trend Micro, BoryptGrab is a C/C++ Windows stealer that exfiltrates browser credentials (with Chrome App Bound Encryption bypass), desktop and extension-based cryptocurrency wallets, Tele
BoryptGrab is a Windows malware family.
Background
Trend Micro reports that BoryptGrab is a C/C++ Windows stealer that harvests browser credentials (including a Chrome App Bound Encryption bypass), desktop and extension-based cryptocurrency wallets, Telegram data, Discord tokens, system information, screenshots, and chosen files from common directories. Distribution occurs through SEO‑poisoned, fake GitHub repositories together with multi‑stage loaders — DLL sideloading, VBS/.NET launchers, and a Golang downloader called "HeaconLoad" — that pull it and related payloads from attacker servers (notably over HTTP on port 5466). The stealer comes in multiple "builds" identified by names such as CryptoByte, Shrek, and Sonic, performs anti‑VM/anti‑analysis checks, and is able to fetch additional components including obfuscated Vidar stealer variants and the TunnesshClient backdoor.
Source: Malpedia (Fraunhofer FKIE).