• News/
  • https://www.bleepingcomputer.com/news/security/malicious-blender-model-files-deliver-stealc-infostealing-malware/

Malicious Blender model files deliver StealC infostealing malware

BleepingComputer
·
Bill Toulas
·
Published Nov 24, 2025
·
Updated

A Russian-linked campaign delivers the StealC V2 information stealer malware through malicious Blender files uploaded to 3D model marketplaces like CGTrader. Blender is a powerful open-source 3D creation suite that can execute Python scripts for automation, custom user interface panels, add-ons, rendering processes, rigging tools, and pipeline integration. If the Auto Run feature is enabled, when a user opens a character rig, a Python script can automatically load the facial controls and custom UI panels with the required buttons and sliders. Despite the potential for abuse, users often activate the Auto Run option for convenience. Researchers at cybersecurity company Morphisec observed attacks using malicious .blend files with embedded Python code that fetches a malware loader from a Cloudflare Workers domain. The loader then fetches a PowerShell script that retrieves two ZIP archives, ZalypaGyliveraV1 and BLENDERX, from attacker-controlled IPs. The archives unpack into the %TEMP% folder and drop LNK files in the Startup directory for persistence. Next, they deploy two payloads, the StealC infostealer and an auxiliary Python stealer, likely used for redundancy. Morphisec researchers report that the StealC malware used in this campaign was the latest variant of the second major version of the malware that was analyzed by Zscaler researchers earlier this year. The latest StealC has expanded its data-stealing capabilities and supports exfiltration from: Despite the malware bei...

Read full article

Affected Software

1 affected component
Blender Foundation Blender

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a campaign that distributes StealC infostealing malware through malicious Blender model files.

2

What type of malware is being delivered through the malicious files?

The malware being delivered is the StealC V2 information stealer.

3

Which program is being exploited to deliver the malware?

The program being exploited is Blender, an open-source 3D creation suite.

4

Where are the malicious Blender files uploaded?

The malicious Blender files are uploaded to 3D model marketplaces such as CGTrader.

5

Who is believed to be behind this malware distribution campaign?

The campaign is linked to Russian cyber actors.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203