logo

Russian-linked Malware Campaign Hides in Blender 3D Files

ID: 12779b28-d275-5085-80c1-88379a90a246

STIX ID: report--12779b28-d275-5085-80c1-88379a90a246

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-11-24

Date Updated: 2026-04-22

...
...

Morphisec researchers uncovered a multi-month campaign weaponizing Blender .blend assets (hosted on marketplaces like CGTrader) that execute concealed Python scripts when Blender Auto Run is enabled; these scripts fetch loaders from workers.dev, deploy PowerShell stages and Python-based stealers (StealC V2), establish persistence via LNK files, and communicate with Pyramid C2 infrastructure—StealC V2 targets numerous browsers, plugins, wallets and clients and is being sold on underground forums, while Morphisec claims its deception-based protections prevented credential exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.