stealc_activity_cluster is an activity cluster associated with campaigns delivering the StealC information stealer through trojanized Blender project files. The operation has involved uploading malicious 3D model files to online asset-sharing platforms and relying on Blender's embedded Python scripting capability to execute code when victims open the files with automatic script execution enabled. The infection chain has used staged payload delivery, including script-based downloaders and archive retrieval, to deploy StealC V2 alongside a secondary Python-based stealer. The cluster has shown overlap with prior activity attributed more broadly to Russian-speaking threat actors, including the use of decoy content, covert background execution, and evasion techniques. Reported victim interests include users in the online gaming and 3D content ecosystem. StealC V2 materially expands collection capabilities and is used to steal data from browsers, browser extensions, cryptocurrency wallet applications, messaging platforms, VPN software, and email clients. Based on the observed tradecraft, the cluster demonstrates initial access through social engineering and trojanized files, followed by payload staging, credential and wallet data theft, and data exfiltration. Attribution beyond a Russian-speaking nexus is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.