A Russian-linked campaign delivers the StealC V2 information stealer malware through malicious Blender files uploaded to 3D model marketplaces like CGTrader. Blender is a powerful open-source 3D creation suite that can execute Python scripts for automation, custom user interface panels, add-ons, rendering processes, rigging tools, and pipeline integration. If the Auto Run feature is enabled, when a user opens a character rig, a Python script can automatically load the facial controls and custom UI panels with the required buttons and sliders. Despite the potential for abuse, users often activate the Auto Run option for convenience. Researchers at cybersecurity company Morphisec observed attacks using malicious .blend files with embedded Python code that fetches a malware loader from a Cloudflare Workers domain. The loader then fetches a PowerShell script that retrieves two ZIP archives, ZalypaGyliveraV1 and BLENDERX, from attacker-controlled IPs. The archives unpack into the %TEMP% folder and drop LNK files in the Startup directory for persistence. Next, they deploy two payloads, the StealC infostealer and an auxiliary Python stealer, likely used for redundancy. Morphisec researchers report that the StealC malware used in this campaign was the latest variant of the second major version of the malware that was analyzed by Zscaler researchers earlier this year. The latest StealC has expanded its data-stealing capabilities and supports exfiltration from: Despite the malware bei...
Malicious Blender model files deliver StealC infostealing malware
BleepingComputer
·Bill Toulas
·Published Nov 24, 2025
·Updated
Affected Software
1 affected component
Blender Foundation Blender
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a campaign that distributes StealC infostealing malware through malicious Blender model files.
2
What type of malware is being delivered through the malicious files?
The malware being delivered is the StealC V2 information stealer.
3
Which program is being exploited to deliver the malware?
The program being exploited is Blender, an open-source 3D creation suite.
4
Where are the malicious Blender files uploaded?
The malicious Blender files are uploaded to 3D model marketplaces such as CGTrader.
5
Who is believed to be behind this malware distribution campaign?
The campaign is linked to Russian cyber actors.