Massive GitHub malware operation spreads BoryptGrab stealer
2026-03-08T14:51:46Z•63909084850aca29015df6afe37220447423beaa752919aaf27161d23cf90bb3
APTBoryptGrabCVE-2026-20122CVE-2026-20128CiscoDindoorDust SpecterGitHubIP camerasIran-linkedLumma StealerMuddyWaterSD-WANWindows Terminalactive-exploitationcredential theftinformation-stealermalwaresocial-engineeringsurveillance intrusion
What happened
Multiple high-impact malware and espionage campaigns reported: Trend Micro uncovered a large campaign distributing the BoryptGrab information stealer via 100+ GitHub repositories to harvest browsers, crypto wallets, system data and files. Microsoft tracked a ClickFix social‑engineering campaign that abuses Windows Terminal to install the Lumma Stealer. Broadcom/Symantec reported Iran‑linked MuddyWater deploying the Dindoor backdoor against U.S. organizations, and Zscaler linked Dust Specter to phishing delivering new malware families targeting Iraqi officials. Check Point observed Iran‑linked,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 63909084850aca29015df6afe37220447423beaa752919aaf27161d23cf90bb3
- Enrichment time
- 2026-03-08T14:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.