logo

Malicious Blender model files deliver StealC infostealing malware

ID: de8c386a-bd05-546a-b97a-b52543416f11

STIX ID: report--de8c386a-bd05-546a-b97a-b52543416f11

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-11-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A Russian-linked campaign is delivering the StealC V2 information stealer through malicious Blender .blend files posted to 3D model marketplaces; when Blender's Auto Run is enabled the embedded Python code fetches a loader from a Cloudflare Workers domain which then pulls a PowerShell script to retrieve ZIP payloads, drop LNK persistence in the Startup folder, and deploy StealC along with an auxiliary Python stealer. The analysed StealC variant supports extensive credential and cryptocurrency wallet theft, targets many browsers and messaging/mail clients, includes a UAC bypass, and was reported as undetected by security engines on VirusTotal, prompting recommendations to disable Auto Run and treat 3D assets like executables.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.