logo

Fake Certificate Loader Hides BlankGrabber Malware Chain

ID: 876c6ba8-b93c-52e3-bfa1-49c71ee8ec1a

STIX ID: report--876c6ba8-b93c-52e3-bfa1-49c71ee8ec1a

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-28

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** Splunk STRT details an active BlankGrabber campaign that abuses certutil to install a Rust stager masquerading as a certificate, unpacks a PyInstaller‑packed infostealer (BlankGrabber) alongside an XWorm backdoor, performs extensive anti‑sandbox and environment checks, harvests credentials/cookies/crypto wallets and other sensitive data, and exfiltrates via Telegram and public file services while establishing persistence and disabling Defender; multiple detections and SHA256 IOCs are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.