Threat Actors Leverage Blender Foundation Files to Deliver Notorious StealC V2 Infostealer
ID: 8bad792f-da90-5e6a-b23d-e027a7724644
STIX ID: report--8bad792f-da90-5e6a-b23d-e027a7724644
Feed Name: cybersecurityNews.com
Cybercriminals are distributing malicious Blender (.blend) files on asset marketplaces that contain auto-executing Python scripts; when opened with Blender’s Auto Run Python Scripts enabled, the files fetch a PowerShell loader which installs a packaged Python environment running StealC V2. The multi-stage campaign (active for ~six months) targets browsers, extensions, crypto wallets, messaging apps and VPNs, employs LNK persistence, ChaCha20-encrypted communications and Pyramid C2, and is linked to Russian-associated operations — users are advised to disable Blender’s auto-run for untrusted files and exercise caution when downloading 3D assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
