New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages Trend Micro Research, News, Perspectives By: Mingyue Shirley Yang 4 March 2026 at 19:00 The BoryptGrab campaign uses fake SEOβoptimized GitHub repositories and deceptive download pages to distribute a dataβstealing malware family that delivers multiple payloads, including a reverse SSH backdoor, to Windows users.