Skip to content

BlankGrabber

BlankGrabber is a Python-based Windows infostealer that emerged by late 2022 and was publicly identified in 2023.

Profile source: Mallory opens in a new tab

BlankGrabber

Family profile

BlankGrabber is a Python-based Windows infostealer that emerged by late 2022 and was publicly identified in 2023. It is commonly packaged with PyInstaller and uses layered obfuscation, encrypted embedded payloads, and deceptive metadata to hinder analysis and appear legitimate. Observed delivery chains include social-engineering-driven distribution through phishing, fake cracked software, Discord-shared archives, fraudulent code repositories, and staged loaders that abuse legitimate Windows utilities before deploying Rust- and Python-based components. Some campaigns have also paired BlankGrabber with XWorm to combine credential theft with broader remote access.

Once executed, BlankGrabber performs extensive anti-analysis and anti-sandbox checks, including inspection of virtualization artifacts, usernames, computer names, UUIDs, and other environment markers associated with analysis systems. It typically creates a mutex to prevent duplicate execution, attempts to obtain elevated privileges, and tampers with Microsoft Defender protections to reduce detection. Reported variants also use persistence mechanisms such as startup-folder placement and Registry Run key execution.

BlankGrabber is designed to harvest a broad range of sensitive information from compromised Windows hosts. Its collection scope includes credentials, cookies, browsing history, autofill data, and other artifacts from Chromium- and Firefox-based browsers; data associated with Discord and Telegram; saved Wi-Fi profiles and passwords; cryptocurrency wallet data and wallet-extension information; clipboard contents; screenshots; webcam captures; system profiling data; and selected local files. The malware has also been reported targeting user data associated with platforms such as Steam and Roblox. Stolen information is exfiltrated to attacker-controlled infrastructure, including channels such as Discord webhooks and Telegram-based mechanisms.

BlankGrabber has been associated with a builder-driven ecosystem that enables operators to customize payload behavior through a graphical interface, contributing to its proliferation and frequent repackaging. Its tradecraft emphasizes scale, accessibility, and effective theft of consumer and prosumer data rather than advanced intrusion sophistication, making it a persistent threat to Windows users and a common example of mass-distributed Python infostealer malware.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Privilege Escalation
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
15 IP / 14 hostnames

Leading locations

  • CN8
  • US8
  • DE4
  • NL3
  • HK2
  • DK1
  • KR1
  • RU1
  • TR1

Leading providers

  • Cloudflare, Inc.5
  • FEMO IT SOLUTIONS LIMITED3
  • Shenzhen Tencent Computer Systems Company Limited3
  • CHINA UNICOM China169 Backbone2
  • Hangzhou Alibaba Advertising Co.,Ltd.2
  • AEZA GROUP LLC1

Infrastructure traits

  • Hosting 24
  • Anycast 6
  • Vpn 1

Samples

Recent associated samples

MITRE ATT&CK

BlankGrabber in ATT&CK

34 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.