Malicious Blender model files deliver StealC infostealing malware
ID: de8c386a-bd05-546a-b97a-b52543416f11
STIX ID: report--de8c386a-bd05-546a-b97a-b52543416f11
Feed Name: Bleeping Computer
A Russian-linked campaign is delivering the StealC V2 information stealer through malicious Blender .blend files posted to 3D model marketplaces; when Blender's Auto Run is enabled the embedded Python code fetches a loader from a Cloudflare Workers domain which then pulls a PowerShell script to retrieve ZIP payloads, drop LNK persistence in the Startup folder, and deploy StealC along with an auxiliary Python stealer. The analysed StealC variant supports extensive credential and cryptocurrency wallet theft, targets many browsers and messaging/mail clients, includes a UAC bypass, and was reported as undetected by security engines on VirusTotal, prompting recommendations to disable Auto Run and treat 3D assets like executables.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
