Russian-linked threat actors have been distributing the StealC V2 infostealer by uploading weaponized Blender .blend files to popular 3D model marketplaces such as CGTrader. These malicious files exploit Blender’s feature that allows embedded Python scripts to run automatically if the 'Auto Run Python Scripts' option is enabled. Unsuspecting users who download and open these files trigger the execution of hidden scripts, which initiate a multi-stage attack chain involving the download of additional payloads, including PowerShell scripts and ZIP archives containing Python-based stealers. The campaign has been active for at least six months and has been linked to previous operations targeting gaming communities with similar tactics and infrastructure.
Morphisec, a cybersecurity firm, successfully detected and blocked several instances of this campaign, providing technical analysis of the attack chain and infrastructure. The StealC V2 malware is capable of stealing credentials and data from over two dozen browsers, more than 15 desktop wallets, and a wide range of plugins and communication applications. This campaign marks the first public attribution of malicious Blender files to StealC and Russian threat actors, highlighting the evolving threat landscape for creative professionals and the risks associated with downloading third-party assets from online marketplaces.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Morphisec published research describing how malicious Blender files abused Auto Run Python Scripts to install StealC V2, along with indicators of compromise such as domains, IPs, and file hashes. The disclosure also warned that this appeared to be the first reported linkage between StealC or Russian-speaking threat actor tradecraft and Blender file abuse.
Morphisec identified the campaign and blocked multiple infection attempts in which embedded Python scripts in .blend files launched a multi-stage chain involving PowerShell, ZIP archives, persistence mechanisms, and Pyramid C2 communications. The firm said its platform stopped the malware before data exfiltration and linked the activity to Russian-speaking threat actor patterns.
Russian-speaking threat actors began distributing weaponized Blender .blend files on 3D model marketplaces such as CGTrader to deliver the StealC V2 infostealer. The campaign was reported as having been active for at least six months before its public disclosure in late November 2025.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcetherecord.media
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcemorphisec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.