SYMBOLCOMMON_NAMEaka. SYNONYMS
win.boryptgrab (Back to overview)

BoryptGrab

VTCollection    

According to Trend Micro, BoryptGrab is a C/C++ Windows stealer that exfiltrates browser credentials (with Chrome App Bound Encryption bypass), desktop and extension-based cryptocurrency wallets, Telegram data, Discord tokens, system information, screenshots, and selected files from common directories. It is delivered via SEO‑poisoned, fake GitHub repositories and multi‑stage loaders (DLL sideloading, VBS/.NET launchers, and a Golang downloader "HeaconLoad") that fetch it and related payloads from attacker servers (notably over HTTP on port 5466). BoryptGrab supports multiple "builds" (tracked via build names like CryptoByte, Shrek, Sonic, etc.), implements anti‑VM/anti‑analysis checks, and can download extra components such as obfuscated Vidar stealer variants and the TunnesshClient backdoor.

References
2026-03-05 ⋅ Trend Micro ⋅ Mingyue Shirley Yang
New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages
BoryptGrab
Yara Rules
[TLP:WHITE] win_boryptgrab_auto (20260917 | Detects win.boryptgrab.)
rule win_boryptgrab_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.boryptgrab."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.boryptgrab"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 90 488d8df8010000 e8???????? 90 488d8d50030000 e8???????? 90 }
            // n = 7, score = 100
            //   90                   | jmp                 0x16e
            //   488d8df8010000       | mov                 dword ptr [ebp - 0x70], ecx
            //   e8????????           |                     
            //   90                   | mov                 byte ptr [esp + 0x40], 0
            //   488d8d50030000       | jg                  0x182
            //   e8????????           |                     
            //   90                   | test                cl, cl

        $sequence_1 = { eb0a b905000000 cd29 488bc8 e8???????? 48895c2478 4c896d80 }
            // n = 7, score = 100
            //   eb0a                 | nop                 
            //   b905000000           | dec                 eax
            //   cd29                 | lea                 edx, [0x128a23]
            //   488bc8               | dec                 eax
            //   e8????????           |                     
            //   48895c2478           | lea                 ecx, [ebp + 0xe90]
            //   4c896d80             | inc                 esp

        $sequence_2 = { e8???????? 48897b78 e9???????? 4863c5 486bf038 8b4320 89443e18 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   48897b78             | and                 al, 5
            //   e9????????           |                     
            //   4863c5               | cmp                 al, 1
            //   486bf038             | jne                 0x58e
            //   8b4320               | test                al, dl
            //   89443e18             | jne                 0x58e

        $sequence_3 = { eb67 408ab598000000 41bb01000000 453bd1 7d10 488b442468 4963ca }
            // n = 7, score = 100
            //   eb67                 | dec                 eax
            //   408ab598000000       | lea                 ecx, [esp + 0x670]
            //   41bb01000000         | nop                 
            //   453bd1               | dec                 esp
            //   7d10                 | mov                 eax, eax
            //   488b442468           | nop                 
            //   4963ca               | dec                 esp

        $sequence_4 = { ba80000000 488bce e8???????? 41807f1900 74bc 498b0e ba80000000 }
            // n = 7, score = 100
            //   ba80000000           | dec                 eax
            //   488bce               | lea                 edx, [ebp - 0x70]
            //   e8????????           |                     
            //   41807f1900           | dec                 eax
            //   74bc                 | cmp                 dword ptr [ebp - 0x58], 0xf
            //   498b0e               | or                  ebx, 4
            //   ba80000000           | jmp                 0x19e

        $sequence_5 = { e8???????? 488b4b18 488bd3 e8???????? 488bce e8???????? 8bc7 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   488b4b18             | mov                 dword ptr [esp + 0x20], 0
            //   488bd3               | inc                 ecx
            //   e8????????           |                     
            //   488bce               | lea                 edx, [ecx + 0x33]
            //   e8????????           |                     
            //   8bc7                 | cmp                 edi, ebp

        $sequence_6 = { 90 488d4d48 e8???????? 90 488d4de8 e8???????? 90 }
            // n = 7, score = 100
            //   90                   | dec                 ecx
            //   488d4d48             | mov                 ecx, esi
            //   e8????????           |                     
            //   90                   | dec                 eax
            //   488d4de8             | mov                 edx, dword ptr [edi + ebx*8 + 8]
            //   e8????????           |                     
            //   90                   | inc                 ebp

        $sequence_7 = { e8???????? 8b7c2444 41b903000000 448b442468 488bcd 897c2420 418d515e }
            // n = 7, score = 100
            //   e8????????           |                     
            //   8b7c2444             | dec                 esp
            //   41b903000000         | mov                 esi, dword ptr [esp + 0x28]
            //   448b442468           | inc                 ebp
            //   488bcd               | test                ecx, ecx
            //   897c2420             | jne                 0x115a
            //   418d515e             | mov                 eax, dword ptr [esp + 0x24]

        $sequence_8 = { 755e 41b848510000 498bd5 488d0d5b2d0e00 e8???????? 8a55e0 80fa03 }
            // n = 7, score = 100
            //   755e                 | dec                 esp
            //   41b848510000         | mov                 dword ptr [esp + 0x58], esp
            //   498bd5               | dec                 ebp
            //   488d0d5b2d0e00       | mov                 eax, esp
            //   e8????????           |                     
            //   8a55e0               | mov                 edx, 0x2c
            //   80fa03               | dec                 ecx

        $sequence_9 = { e8???????? c6474100 85f6 750a 4439ac24a0000000 7503 448bf6 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   c6474100             | xor                 eax, eax
            //   85f6                 | mov                 eax, ecx
            //   750a                 | inc                 ebp
            //   4439ac24a0000000     | mov                 ebp, ebx
            //   7503                 | not                 eax
            //   448bf6               | mov                 dword ptr [esi + 0x44], eax

    condition:
        7 of them and filesize < 5648384
}
Download all Yara Rules