Massive GitHub malware operation spreads BoryptGrab stealer

2026-03-08T14:51:46Z63909084850aca29015df6afe37220447423beaa752919aaf27161d23cf90bb3
APTBoryptGrabCVE-2026-20122CVE-2026-20128CiscoDindoorDust SpecterGitHubIP camerasIran-linkedLumma StealerMuddyWaterSD-WANWindows Terminalactive-exploitationcredential theftinformation-stealermalwaresocial-engineeringsurveillance intrusion

What happened

Multiple high-impact malware and espionage campaigns reported: Trend Micro uncovered a large campaign distributing the BoryptGrab information stealer via 100+ GitHub repositories to harvest browsers, crypto wallets, system data and files. Microsoft tracked a ClickFix social‑engineering campaign that abuses Windows Terminal to install the Lumma Stealer. Broadcom/Symantec reported Iran‑linked MuddyWater deploying the Dindoor backdoor against U.S. organizations, and Zscaler linked Dust Specter to phishing delivering new malware families targeting Iraqi officials. Check Point observed Iran‑linked,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
63909084850aca29015df6afe37220447423beaa752919aaf27161d23cf90bb3
Enrichment time
2026-03-08T14:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.