Over 100 GitHub Repositories Distributing BoryptGrab Stealer

2026-03-07T13:24:11Z1838adde9d9f8947c477a46f796fc3e502e9034563af42238688148f0b041627
boryptgrabbrowser-datacisacorunacrypto-walletsdata-breachexploitfbi-investigationgithubicsiosiranian-aptkevknown-exploited-vulnerabilitymalwarenation-staterockwellstealer

What happened

Multiple active threats and notable cybersecurity developments: researchers found over 100 GitHub repositories distributing the BoryptGrab stealer (exfiltrates browser data, crypto wallets, system info and user files). CISA added 23 iOS vulnerabilities exploited by the nation‑state-grade Coruna exploit kit to its KEV catalog (affecting iOS 13–17.2.1). A Rockwell ICS vulnerability disclosed and mitigated in 2021 is now observed being exploited in the wild. The FBI is investigating suspicious activity on a system storing sensitive surveillance information, and an Iranian APT has compromised at‑U

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
1838adde9d9f8947c477a46f796fc3e502e9034563af42238688148f0b041627
Enrichment time
2026-03-07T13:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Over 100 GitHub Repositories Distributing BoryptGrab Stealer · Baitaphish