logo

BlankGrabber Stealer Uses Fake Certificate Loader to Hide Malware Delivery Chain

ID: dffe2c4d-2f21-50e3-bfa3-2912dbc398d5

STIX ID: report--dffe2c4d-2f21-50e3-bfa3-2912dbc398d5

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

BlankGrabber is a Python-based infostealer that uses a deceptive certutil-based batch loader and multi-stage obfuscation to deliver an AES-encrypted Python payload and the XWorm RAT; it targets browser credentials, session tokens, wallets, clipboard data, screenshots and more, employs anti-sandbox/virtualization checks, disables Windows Defender, modifies hosts for evasion, and persists via startup — distributed via social engineering (cracked software, Discord, fraudulent GitHub). Defenders should look for certutil decoding non-certificate data, anomalous WinRAR activity, PowerShell commands disabling Defender, startup persistence, and connections to file-sharing or Telegram APIs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.