Russian-linked Malware Campaign Hides in Blender 3D Files
ID: 12779b28-d275-5085-80c1-88379a90a246
STIX ID: report--12779b28-d275-5085-80c1-88379a90a246
Feed Name: Infosecurity Magazine (News)
Morphisec researchers uncovered a multi-month campaign weaponizing Blender .blend assets (hosted on marketplaces like CGTrader) that execute concealed Python scripts when Blender Auto Run is enabled; these scripts fetch loaders from workers.dev, deploy PowerShell stages and Python-based stealers (StealC V2), establish persistence via LNK files, and communicate with Pyramid C2 infrastructure—StealC V2 targets numerous browsers, plugins, wallets and clients and is being sold on underground forums, while Morphisec claims its deception-based protections prevented credential exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
