Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Operation Code

Operation Code Vendor Cyber Rating & Cyber Score

operationcode.org

Operation Code's mission is to provide active workforce development for military service members, Veterans and military families to enter the tech industry, grow in their careers and leadership and deploy the future. Veteran-founded and led, Operation Code believes Veterans trained with technical skills can help close the nation's technical talent shortage and give back to our communities through our service-oriented programs and initiatives. Through our new pilot program, Project Rebuild, we are pairing up our military mentors with Afghan SIV refugees to help rebuild their lives after 20 years of war, to start a new career and enter the tech industry.


Operation Code A.I CyberSecurity Scoring

Operation Code
Company Information
Website:https://operationcode.org
Employees number:11
Number of followers:3,385
NAICS:5112
Industry Type:Software Development
Homepage:operationcode.org
Operation Code Risk Score (AI oriented)
Between 700 and 749
logo
Operation CodeSoftware Development
Updated:
28/03/2026
737/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Operation Code Global Score (TPRM)
xxxx
logo
Operation CodeSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Operation CodeModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
739Before Incident
AUGUST 2026
739Before Incident
JULY 2026
739Before Incident
JUNE 2026
738Before Incident
MAY 2026
738Before Incident
APRIL 2026
737Before Incident
MARCH 2026
737Before Incident
FEBRUARY 2026
737Before Incident
JANUARY 2026
736Before Incident
DECEMBER 2025
736Before Incident
NOVEMBER 2025
735Before Incident
OCTOBER 2025
735Before Incident
APRIL 2025
750Before Incident
Cyber Attack
01 Apr 2025Operation Code
Mozilla, GitHub, Brave Software, Ledger, Trezor and Opera: BoryptGrab Malware Abuses GitHub to Steal Browser and Crypto Wallet Data

New Windows Stealer 'BoryptGrab' Spreads via Fake GitHub Repositories in Large-Scale Campaign

731After Incident
CRITICAL-19
THEBRATREMOZGITOPE1773066485
New Windows Stealer "BoryptGrab" Spreads via Fake GitHub Repositories in Large-Scale Campaign A sophisticated malware campaign is distributing BoryptGrab, a Windows information stealer, through fake GitHub repositories masquerading as free tools, game cheats, and cracked software. The operation, active since at least April 2025, leverages SEO-optimized README files to rank malicious repositories near legitimate projects in search results, tricking users into downloading infected ZIP archives. ### How the Attack Works Attackers have created over 100 public GitHub repositories advertising enticing but fake software, including: - "Voicemod Pro download tool" - "Valorant performance boost" - "CS2 skin changers" - Cracked utilities and cheat-style tools Victims are redirected through GitHub-hosted pages containing Russian-language comments and base64/AES-based URL redirection logic, ultimately landing on a fake GitHub download page that dynamically generates a malicious ZIP file. ### Infection Chain & Malware Capabilities Once executed, the malware employs multiple infection vectors: - DLL side-loading (via a malicious `libcurl.dll` that decrypts an embedded launcher using XOR + AES-CBC). - VBS/PowerShell downloaders that bypass security controls (e.g., adding Microsoft Defender exclusions) and fetch the BoryptGrab stealer from attacker-controlled servers. - Golang-based downloader (HeaconLoad), which persists via Run-key registry entries and scheduled tasks, beaconing to command-and-control (C2) servers on port 8088. - TunnesshClient, a PyInstaller-packed backdoor that establishes reverse SSH tunnels, allowing attackers to execute commands, exfiltrate files, or use the victim as a SOCKS5 proxy. Some variants also deliver obfuscated Vidar stealer payloads via an `/api/custom_exe?build={BUILD_NAME}` endpoint, using XOR encryption and dynamic API resolution to evade detection. ### What BoryptGrab Steals The C/C++-based stealer includes anti-VM and anti-analysis checks and targets: - Browser data (Chrome, Edge, Firefox, Opera, Brave, Vivaldi, Yandex, etc.), including stored passwords (bypassing Chrome’s App-Bound Encryption). - Cryptocurrency wallets (Exodus, Electrum, Ledger Live, Atomic, Binance, Trezor, and dozens more). - System details, screenshots, Telegram data, and Discord tokens. - Files with specific extensions (via a "Filegraber" module). - Installed applications and hardcoded timestamps. Collected data is compressed and exfiltrated to attacker servers, often followed by the deployment of TunnesshClient for persistent remote access. ### Attribution & Infrastructure - Russian-language comments and log strings in malware components, along with Russian-hosted IP addresses, suggest a Russian-speaking threat actor, though formal attribution remains unconfirmed. - C2 servers communicate over ports 5466 and 8088, with build names (e.g., Shrek, Leon, CryptoByte, Sonic, Yaropolk) used to track infection branches. The campaign demonstrates a mature, evolving ecosystem, combining SEO poisoning, multi-stage downloaders, and SSH-based backdoors to maximize persistence and data theft.
INCIDENT DETAILS -
TYPE
Malware Campaign
MOTIVATION
Data theftFinancial gainPersistent remote access
IMPACT
Browser data (passwords, cookies, autofill)Cryptocurrency walletsTelegram dataDiscord tokensSystem detailsScreenshotsFiles with specific extensionsWindows systemsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Browser dataCryptocurrency walletsMessaging app dataSystem informationFilesSensitivity Of Data: HighXORAES-CBC

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Operation Code ?
?
What was Operation Code's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Operation Code's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Operation Code's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Operation Code ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Operation Code's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?