BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New StealC V2 Malware Targets Blender Users via Malicious Files

Cybercriminals exploit Blender's .blend files with embedded Python scripts to deploy StealC V2 malware targeting 3D asset users on platforms like CGTrader, stealing extensive data and leveraging Blender's Auto Run feature for automatic execution.

  • Hackers have launched a campaign using malicious .blend files to spread the StealC V2 information stealer.
  • The attack targets users downloading 3D assets from sites like CGTrader, relying on embedded Python scripts executed by Blender software.
  • The Malware steals data from browsers, cryptocurrency wallets, messaging apps, VPNs, and email clients.
  • The campaign shows links to previous Russian-speaking threat actors known for similar tactics.
  • Blender’s Auto Run feature enables the automatic execution of harmful scripts contained in .blend files.

Cybersecurity researchers uncovered a campaign active for over six months exploiting Blender Foundation’s file format. Malicious .blend files were distributed on platforms such as CGTrader. When opened using the Blender 3D creation suite with its Auto Run feature enabled, these files execute embedded Python scripts designed to install the StealC V2 information stealer.

- Advertisement -

The attackers upload .blend files containing a harmful script named “Rig_Ui.py.” Upon opening, this script runs automatically and triggers a PowerShell command that downloads two ZIP archives. One contains the StealC V2 payload, while the other installs a secondary Python-based stealer on the infected device. StealC V2 gathers information from 23 web browsers, 100 plugins and extensions, 15 cryptocurrency wallet applications, various messaging services, VPN software, and email clients.

According to statements from Morphisec researcher Shmuel Uzan, this campaign shares tactics with a previous operation linked to Russian-speaking threat groups. Similarities include the use of decoy documents, stealth techniques, and background malware execution. Those earlier attacks impersonated organizations like the Electronic Frontier Foundation (EFF) to target online gamers.

The risk arises because Blender permits Python scripts inside .blend files for advanced tasks like character rigging and automation. This capability also allows arbitrary scripts to run, which can be exploited if the Auto Run option is turned on. Blender has acknowledged this security risk on its official documentation, explaining the unrestricted nature of embedded Python scripts.

Users are advised to keep the Auto Run feature disabled unless files are from trusted sources to reduce infection risk. Attackers leverage Blender’s typical use on physical machines with GPUs to bypass Sandbox and virtual environments, increasing the potential impact of this malicious campaign. For further details, see the Morphisec report and Blender’s security documentation.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Targets $92,630 If Key Support Holds

Bitcoin rebounded 6.5% to near $62,950 on Sunday, holding above the critical $60,000 support.Analysts...

Bitcoin Braced for Deeper Purge as Losses Lag 2022 Peak

Bitcoin’s 2026 realized losses of $174 billion have not yet surpassed the 2022 record...

Panel: Bitcoin Could Crash to $30K or Soar to $130K

Patrick Bet-David suggested Bitcoin's price could swing dramatically, falling to $30,000 or surging to...

Bitcoin Plunges Amid Selloff; All Eyes on Saylor’s Next Move

Bitcoin plunged over 50% from its October 2025 peak of $126,000, wiping $2 trillion...

Broadcom Earnings Spark Semiconductor Stock Plunge

Broadcom's Q2 earnings, which beat expectations, triggered a 12.6% crash in its own stock...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading