Russian Threat Actors Weaponize Blender Files to Spread StealC V2 Infostealer

Listen to this Post

Featured Image

Introduction

A new cybersecurity alert highlights an unusual but highly effective malware campaign targeting 3D design software users. Russian threat actors are leveraging Blender—a widely-used, open-source 3D modeling suite—to spread the latest variant of the StealC V2 infostealer. By embedding malicious Python scripts inside .blend files, attackers exploit Blender’s automation features to steal sensitive data, including browser credentials, crypto-wallets, messaging apps, and VPN clients. This campaign has been ongoing for at least six months and represents a sophisticated evolution in malware distribution tactics.

the Threat

Cybersecurity firm Morphisec has reported a sophisticated malware campaign using weaponized Blender files to deliver StealC V2. Attackers upload malicious .blend files to 3D model marketplaces like CGTrader, exploiting Blender’s ability to run Python scripts automatically. When unsuspecting users download and open these files with “Auto Run Python Scripts” enabled, embedded code executes silently, initiating the malware chain.

The Rig_Ui.py script, commonly embedded, downloads a PowerShell loader, which in turn retrieves ZIP archives containing StealC V2 and auxiliary Python stealers. These payloads extract into temporary directories, establish persistence via hidden startup links, and use Pyramid C2 to fetch encrypted modules. The latest StealC V2 variant, updated through mid-2025, dramatically expands its capabilities. It can exfiltrate credentials from over 23 browsers, 100+ crypto-wallet extensions, 15 wallet apps, and messaging and VPN clients including Telegram, Discord, ProtonVPN, OpenVPN, and Thunderbird. Enhanced UAC bypass techniques allow it to operate silently on target systems.

Previous warnings about malicious Blender files were not linked to Russian threat actors until now. Evidence ties this campaign to earlier Russian operations, including fake EFF lures targeting Albion Online players. The campaign emphasizes decoys, evasion techniques, and stealth execution to avoid detection. Many samples analyzed on VirusTotal had extremely low detection rates, making this a particularly dangerous threat for Blender users. Morphisec recommends disabling Auto Run Python Scripts unless the file source is fully trusted.

What Undercode Say:

This campaign represents a shift in malware strategy, moving from traditional phishing and email attacks to exploiting niche creative software ecosystems. Blender, as a cross-platform 3D creation suite with an open-source foundation, is widely trusted, which makes this attack vector particularly insidious. The use of Python scripts within .blend files highlights how legitimate features can be weaponized for cybercrime.

The attackers’ chain of execution is both sophisticated and modular. By embedding a Python script to initiate a PowerShell loader, they bypass traditional endpoint security, which often focuses on executable files rather than scripting languages within design software. The deployment of Pyramid C2 and encrypted modules ensures persistence and communication without triggering standard detection protocols, illustrating the growing complexity of infostealers.

StealC V2’s expanded capabilities reflect a strategic focus on monetizable targets: browsers, crypto-wallets, and communication platforms. Each category represents a high-value attack surface. Targeting browsers with over 23 supported variants, including server-side credential decryption, allows attackers to harvest corporate and personal credentials seamlessly. Crypto-wallet theft aligns with the rising trend of cryptocurrency-related cybercrime, while messaging and VPN client exfiltration indicates an interest in both personal privacy and potential espionage.

From a defensive perspective, this campaign underscores the need for holistic endpoint protection. Security solutions must now account for unconventional attack vectors like 3D design files, especially in industries relying heavily on creative software. Disabling Auto Run Python Scripts, validating file sources, and sandbox testing of .blend files are immediate mitigation steps.

Moreover, the campaign demonstrates an evolution in attacker behavior: targeting highly specialized user communities that may not expect malware threats. Traditional malware targeting office productivity software or operating system vulnerabilities is giving way to attacks on niche tools, exploiting trust and familiarity to bypass conventional detection.

This incident also raises questions about marketplace security. CGTrader and similar 3D asset platforms now need to consider stricter validation, user education, and scanning of uploaded files. Without intervention, attackers could exploit other creative software ecosystems in similar ways, creating a persistent threat vector for designers, animators, and engineers worldwide.

Finally, the operational longevity of this campaign—six months and counting—shows the resilience of attackers in maintaining stealthy operations. Continuous monitoring, threat intelligence sharing, and proactive endpoint hygiene are critical for preventing further spread of such advanced infostealers.

Fact Checker Results:

✅ StealC V2 is actively used in malware campaigns targeting Blender users.
✅ Malicious .blend files exploit Python scripts to execute automatically.
❌ There is no evidence that all Blender files are unsafe—only those from untrusted sources with embedded scripts.

Prediction

📊 The trend of weaponizing niche creative software is likely to grow. Expect other open-source and widely-used tools to become targets for sophisticated infostealers. Developers and marketplaces will need enhanced security protocols, while users must adopt stricter operational hygiene. Cybercriminals may expand targeting to VR, CAD, and animation platforms, increasing the complexity and financial impact of malware campaigns.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon