CL A.I CyberSecurity Scoring
CL
Company Information
Website:https://thecyberledger.in/
Employees number:2
Number of followers:464
NAICS:541514
Industry Type:Computer and Network Security
Homepage:thecyberledger.in
CL Risk Score (AI oriented)
Between 700 and 749
CLComputer and Network Security
Updated:
03/04/2026
03/04/2026
737/1000
Moderate
Ba
CL Global Score (TPRM)
xxxx
CLComputer and Network Security
Score locked

CLModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
738
MAY 2026
737
APRIL 2026
737
MARCH 2026
736
FEBRUARY 2026
736
JANUARY 2026
736
DECEMBER 2025
735
NOVEMBER 2025
735
OCTOBER 2025
734
SEPTEMBER 2025
734
AUGUST 2025
733
JULY 2025
733
APRIL 2025
748
Cyber Attack
01 Apr 2025 • CL
Mozilla, GitHub, Brave Software, Ledger, Trezor and Opera: BoryptGrab Malware Abuses GitHub to Steal Browser and Crypto Wallet Data
New Windows Stealer 'BoryptGrab' Spreads via Fake GitHub Repositories in Large-Scale Campaign
730
CRITICAL-18
THEBRATREMOZGITOPE1773066485
New Windows Stealer "BoryptGrab" Spreads via Fake GitHub Repositories in Large-Scale Campaign
A sophisticated malware campaign is distributing BoryptGrab, a Windows information stealer, through fake GitHub repositories masquerading as free tools, game cheats, and cracked software. The operation, active since at least April 2025, leverages SEO-optimized README files to rank malicious repositories near legitimate projects in search results, tricking users into downloading infected ZIP archives.
### How the Attack Works
Attackers have created over 100 public GitHub repositories advertising enticing but fake software, including:
- "Voicemod Pro download tool"
- "Valorant performance boost"
- "CS2 skin changers"
- Cracked utilities and cheat-style tools
Victims are redirected through GitHub-hosted pages containing Russian-language comments and base64/AES-based URL redirection logic, ultimately landing on a fake GitHub download page that dynamically generates a malicious ZIP file.
### Infection Chain & Malware Capabilities
Once executed, the malware employs multiple infection vectors:
- DLL side-loading (via a malicious `libcurl.dll` that decrypts an embedded launcher using XOR + AES-CBC).
- VBS/PowerShell downloaders that bypass security controls (e.g., adding Microsoft Defender exclusions) and fetch the BoryptGrab stealer from attacker-controlled servers.
- Golang-based downloader (HeaconLoad), which persists via Run-key registry entries and scheduled tasks, beaconing to command-and-control (C2) servers on port 8088.
- TunnesshClient, a PyInstaller-packed backdoor that establishes reverse SSH tunnels, allowing attackers to execute commands, exfiltrate files, or use the victim as a SOCKS5 proxy.
Some variants also deliver obfuscated Vidar stealer payloads via an `/api/custom_exe?build={BUILD_NAME}` endpoint, using XOR encryption and dynamic API resolution to evade detection.
### What BoryptGrab Steals
The C/C++-based stealer includes anti-VM and anti-analysis checks and targets:
- Browser data (Chrome, Edge, Firefox, Opera, Brave, Vivaldi, Yandex, etc.), including stored passwords (bypassing Chrome’s App-Bound Encryption).
- Cryptocurrency wallets (Exodus, Electrum, Ledger Live, Atomic, Binance, Trezor, and dozens more).
- System details, screenshots, Telegram data, and Discord tokens.
- Files with specific extensions (via a "Filegraber" module).
- Installed applications and hardcoded timestamps.
Collected data is compressed and exfiltrated to attacker servers, often followed by the deployment of TunnesshClient for persistent remote access.
### Attribution & Infrastructure
- Russian-language comments and log strings in malware components, along with Russian-hosted IP addresses, suggest a Russian-speaking threat actor, though formal attribution remains unconfirmed.
- C2 servers communicate over ports 5466 and 8088, with build names (e.g., Shrek, Leon, CryptoByte, Sonic, Yaropolk) used to track infection branches.
The campaign demonstrates a mature, evolving ecosystem, combining SEO poisoning, multi-stage downloaders, and SSH-based backdoors to maximize persistence and data theft.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CL ??
What was CL's A.I Rankiteo Cyber Score in May 2026 ??
What was CL's A.I Rankiteo Cyber Score in April 2026 ??
What was CL's A.I Rankiteo Cyber Score in March 2026 ??
What was CL's A.I Rankiteo Cyber Score in February 2026 ??
What was CL's A.I Rankiteo Cyber Score in January 2026 ??
What was CL's A.I Rankiteo Cyber Score in December 2025 ??
What was CL's A.I Rankiteo Cyber Score in November 2025 ??
What was CL's A.I Rankiteo Cyber Score in October 2025 ??
What was CL's A.I Rankiteo Cyber Score in September 2025 ??
What was CL's A.I Rankiteo Cyber Score in August 2025 ??
What was CL's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on CL's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CL ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CL's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?