BlankGrabber Stealer Uses Fake Certificate Loader to Hide Malware Delivery Chain
ID: dffe2c4d-2f21-50e3-bfa3-2912dbc398d5
STIX ID: report--dffe2c4d-2f21-50e3-bfa3-2912dbc398d5
Feed Name: cybersecurityNews.com
BlankGrabber is a Python-based infostealer that uses a deceptive certutil-based batch loader and multi-stage obfuscation to deliver an AES-encrypted Python payload and the XWorm RAT; it targets browser credentials, session tokens, wallets, clipboard data, screenshots and more, employs anti-sandbox/virtualization checks, disables Windows Defender, modifies hosts for evasion, and persists via startup — distributed via social engineering (cracked software, Discord, fraudulent GitHub). Defenders should look for certutil decoding non-certificate data, anomalous WinRAR activity, PowerShell commands disabling Defender, startup persistence, and connections to file-sharing or Telegram APIs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
