logo

Inside the Rapid Evolution of the BlankGrabber Stealer

ID: ad6250d8-61b3-5802-a458-9354f0ab470a

STIX ID: report--ad6250d8-61b3-5802-a458-9354f0ab470a

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-03

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive Summary:** Splunk Threat Research Team analyzes BlankGrabber, a rapidly evolving, modular Python infostealer distributed via social engineering and weaponized GitHub/Discord artifacts; it uses a certutil-based multi-stage loader, exfiltrates browser credentials, Discord tokens and system metadata, and sends stolen data via Telegram bot C2 or uploads to public file hosts, often packaging results in password-protected archives to hinder analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.