Inside the Rapid Evolution of the BlankGrabber Stealer
ID: ad6250d8-61b3-5802-a458-9354f0ab470a
STIX ID: report--ad6250d8-61b3-5802-a458-9354f0ab470a
Feed Name: securityonline.info
Threat Score
**Executive Summary:** Splunk Threat Research Team analyzes BlankGrabber, a rapidly evolving, modular Python infostealer distributed via social engineering and weaponized GitHub/Discord artifacts; it uses a certutil-based multi-stage loader, exfiltrates browser credentials, Discord tokens and system metadata, and sends stolen data via Telegram bot C2 or uploads to public file hosts, often packaging results in password-protected archives to hinder analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
