216.73.217.22

The Certificate Decoding Illusion: How Blank Grabber Stealer Hides Its Loader

· Published 27/03/2026 08:45 · Modified 27/03/2026 09:29

Export JSON

Essential information

Published
27/03/2026 08:45
Modified
27/03/2026 09:29
Tags
2026-03-27 blankgrabber information stealer xworm
Related entities
2 vulnerabilities (cve), 1 observables, 2 malware

Description

, a Python-based , employs sophisticated techniques to evade detection and exfiltrate sensitive data. It uses a multi-stage infection chain, starting with a batch file loader that disguises the payload as certificate data. The malware implements anti-analysis measures, including sandbox and virtualization checks. It harvests a wide range of data, including browser information, system details, and credentials from various applications. utilizes Windows Management Instrumentation for system discovery, captures screenshots and webcam images, and attempts to disable Windows Defender. The malware achieves persistence through startup folder manipulation and exfiltrates data using Telegram bots and public web services.

External references