Skip to content

Malware

BoryptGrab

According to Trend Micro, BoryptGrab is a C/C++ Windows stealer that exfiltrates browser credentials (with Chrome App Bound Encryption bypass), desktop and extension-based cryptocurrency wallets, Tele

BoryptGrab is a Windows malware family.

Background

Trend Micro reports that BoryptGrab is a C/C++ Windows stealer that harvests browser credentials (including a Chrome App Bound Encryption bypass), desktop and extension-based cryptocurrency wallets, Telegram data, Discord tokens, system information, screenshots, and chosen files from common directories. Distribution occurs through SEO‑poisoned, fake GitHub repositories together with multi‑stage loaders — DLL sideloading, VBS/.NET launchers, and a Golang downloader called "HeaconLoad" — that pull it and related payloads from attacker servers (notably over HTTP on port 5466). The stealer comes in multiple "builds" identified by names such as CryptoByte, Shrek, and Sonic, performs anti‑VM/anti‑analysis checks, and is able to fetch additional components including obfuscated Vidar stealer variants and the TunnesshClient backdoor.


Source: Malpedia (Fraunhofer FKIE).