logo

Threat Actors Leverage Blender Foundation Files to Deliver Notorious StealC V2 Infostealer

ID: 8bad792f-da90-5e6a-b23d-e027a7724644

STIX ID: report--8bad792f-da90-5e6a-b23d-e027a7724644

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-11-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Cybercriminals are distributing malicious Blender (.blend) files on asset marketplaces that contain auto-executing Python scripts; when opened with Blender’s Auto Run Python Scripts enabled, the files fetch a PowerShell loader which installs a packaged Python environment running StealC V2. The multi-stage campaign (active for ~six months) targets browsers, extensions, crypto wallets, messaging apps and VPNs, employs LNK persistence, ChaCha20-encrypted communications and Pyramid C2, and is linked to Russian-associated operations — users are advised to disable Blender’s auto-run for untrusted files and exercise caution when downloading 3D assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.