Hackers linked to Russia have taken advantage of this a well-known 3D design tool for infecting animators, video game developers, and visual effects studios with malwareto get information.
This is according to a report by the Israeli cyber security company Morphisec, where it warns that over the past six months it has blocked several companies in which Attackers used Blender project files to spread StealC V2 malware.
Blender is a free and open source program widely used in the industry for 3D modeling and animation.
Attackers uploaded malicious files with the .blend extension, which include Python scripts, to sites where designers download 3D models, such as CGTrader.
If the user has Auto Run Python Scripts enabled in the application, The script runs automatically when the file is opened. This creates a chain of infection. which causes the StealC V2 malware to download and run.
StealC V2, a malware worth its price
This malicious tool carries offered on dark web forums since 2023 for around $200 per month.
Some cybercriminal groups have used it to hijack browser data, attack cryptocurrency wallets, and hack messaging apps, VPN clients, and web plugins. As a rule, their victims are located in Western Europe and North America, as well as in Asia.
Its code prevents the infection of computers configured in Russian, Ukrainian, Belarusian or Kazakh languages (which is common in operations of Russian origin).
Morphisec, who disclosed the company, recommends downloading 3D models only from trusted sources and keep your computer security software up to date to avoid becoming a victim of this type of attack.

