By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware
Computing

Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware

News Room
Last updated: 2025/11/25 at 7:10 AM
News Room Published 25 November 2025
Share
Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware
SHARE

Nov 25, 2025Ravie LakshmananMalware / Browser Security

Cybersecurity researchers have disclosed details of a new campaign that has leveraged Blender Foundation files to deliver an information stealer known as StealC V2.

“This ongoing operation, active for at least six months, involves implanting malicious .blend files on platforms like CGTrader,” Morphisec researcher Shmuel Uzan said in a report shared with The Hacker News.

“Users unknowingly download these 3D model files, which are designed to execute embedded Python scripts upon opening in Blender — a free, open-source 3D creation suite.”

DFIR Retainer Services

The cybersecurity company said the activity shares similarities with a prior campaign linked to Russian-speaking threat actors that involved impersonating the Electronic Frontier Foundation (EFF) to target the online gaming community and infect them with StealC and Pyramid C2.

This assessment is based on tactical similarities in both campaigns, including using decoy documents, evasive techniques, and background execution of malware.

The latest set of attacks abuses the ability to embed Python scripts in .blend files like character rigs that are automatically executed when they are opened in scenarios where the Auto Run option is enabled. This behavior can be dangerous as it opens the door to the execution of arbitrary Python scripts.

The security risk has been acknowledged by Blender in its own documentation, which states: “The ability to include Python scripts within blend-files is valuable for advanced tasks such as rigging and automation. However, it poses a security risk since Python does not restrict what a script can do.”

The attack chains essentially involve uploading malicious .blend files to free 3D asset sites such as CGTrader containing a malicious “Rig_Ui.py” script, which is executed as soon as they are opened with Blender’s Auto Run feature enabled. This, in turn, fetches a PowerShell script to download two ZIP archives.

CIS Build Kits

While one of the ZIP files contains a payload for StealC V2, the second archive deploys a secondary Python-based stealer on the compromised host. The updated version of StealC, first announced in late April 2025, supports a wide range of information gathering features, allowing data to be extracted from 23 browsers, 100 web plugins and extensions, 15 cryptocurrency wallet apps, messaging services, VPNs, and email clients.

“Keep Auto Run disabled unless the file source is trusted,” Morphisec said. “Attackers exploit Blender that typically runs on physical machines with GPUs, bypassing sandboxes and virtual environments.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Free TV box sells out in HOURS as creator says gadget ‘far exceeded expectation’ Free TV box sells out in HOURS as creator says gadget ‘far exceeded expectation’
Next Article If Google’s Aluminium OS has these 5 features, I’ll ditch Windows for good If Google’s Aluminium OS has these 5 features, I’ll ditch Windows for good
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Best Apple deal: Get 3 months of Apple TV with the  AirPods
Best Apple deal: Get 3 months of Apple TV with the $69 AirPods
News
Amazon slashes new M5 MacBook Pro to ,399, save 0 for Black Friday
Amazon slashes new M5 MacBook Pro to $1,399, save $200 for Black Friday
News
Nix Package Tool Approved For Availability In Fedora 44
Nix Package Tool Approved For Availability In Fedora 44
Computing
Your Spotify Subscription Might Get More Expensive Soon – BGR
Your Spotify Subscription Might Get More Expensive Soon – BGR
News

You Might also Like

Nix Package Tool Approved For Availability In Fedora 44
Computing

Nix Package Tool Approved For Availability In Fedora 44

3 Min Read
Safaricom pushes M-PESA into an API-first future with Daraja 3.0
Computing

Safaricom pushes M-PESA into an API-first future with Daraja 3.0

4 Min Read
The TechBeat: Stop Building Your Product for Yourself: Why Most Early-Stage Startups Fail at Marketing (11/25/2025) | HackerNoon
Computing

The TechBeat: Stop Building Your Product for Yourself: Why Most Early-Stage Startups Fail at Marketing (11/25/2025) | HackerNoon

7 Min Read
Uncommon Thinkers: How Portal’s Jeff Thornburg plans to harness the heat of the sun in the cold of space
Computing

Uncommon Thinkers: How Portal’s Jeff Thornburg plans to harness the heat of the sun in the cold of space

19 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?