Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 15 IP / 14 hostnames
BlankGrabber is a Python-based Windows infostealer that emerged by late 2022 and was publicly identified in 2023.
Profile source: Mallory opens in a new tabBlankGrabber
BlankGrabber is a Python-based Windows infostealer that emerged by late 2022 and was publicly identified in 2023. It is commonly packaged with PyInstaller and uses layered obfuscation, encrypted embedded payloads, and deceptive metadata to hinder analysis and appear legitimate. Observed delivery chains include social-engineering-driven distribution through phishing, fake cracked software, Discord-shared archives, fraudulent code repositories, and staged loaders that abuse legitimate Windows utilities before deploying Rust- and Python-based components. Some campaigns have also paired BlankGrabber with XWorm to combine credential theft with broader remote access.
Once executed, BlankGrabber performs extensive anti-analysis and anti-sandbox checks, including inspection of virtualization artifacts, usernames, computer names, UUIDs, and other environment markers associated with analysis systems. It typically creates a mutex to prevent duplicate execution, attempts to obtain elevated privileges, and tampers with Microsoft Defender protections to reduce detection. Reported variants also use persistence mechanisms such as startup-folder placement and Registry Run key execution.
BlankGrabber is designed to harvest a broad range of sensitive information from compromised Windows hosts. Its collection scope includes credentials, cookies, browsing history, autofill data, and other artifacts from Chromium- and Firefox-based browsers; data associated with Discord and Telegram; saved Wi-Fi profiles and passwords; cryptocurrency wallet data and wallet-extension information; clipboard contents; screenshots; webcam captures; system profiling data; and selected local files. The malware has also been reported targeting user data associated with platforms such as Steam and Roblox. Stolen information is exfiltrated to attacker-controlled infrastructure, including channels such as Discord webhooks and Telegram-based mechanisms.
BlankGrabber has been associated with a builder-driven ecosystem that enables operators to customize payload behavior through a graphical interface, contributing to its proliferation and frequent repackaging. Its tradecraft emphasizes scale, accessibility, and effective theft of consumer and prosumer data rather than advanced intrusion sophistication, making it a persistent threat to Windows users and a common example of mass-distributed Python infostealer malware.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 33ecb34cf22a8f1352d5f2e998498024881af0fa62350656756f6c2b1c76dde1 4763418f81fac1596b9e46138afd0e35d3d646702c35938d8762d9dbe32912e0 6d10629ab338ff1751e4cf6604986a45653a933f3b4e835a12dce58a83657017 a931e66fe6f5c347eb721c664a09b1916485b3076107456f10111baa22c9bc02 c031d1e6e9b451034ff2da73a2aa1a87256e00729ebeca09170429434846749d MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.