The Containment Era is here. →Explore

Executive Summary

In late 2025, cybersecurity researchers identified a prolonged campaign in which attackers weaponized Blender 3D asset files (.blend) on popular asset-sharing platforms such as CGTrader. By implanting malicious files that executed the StealC V2 information-stealing malware, threat actors compromised unsuspecting users when they opened downloaded assets. Over at least six months, the campaign enabled attackers to harvest login credentials, browser data, and sensitive information from artists and professionals in gaming, animation, and design industries, leading to significant data theft and potential downstream attacks on organizations relying on Blender assets.

This incident highlights the growing abuse of trusted creative software supply chains and open asset marketplaces. As creative and industrial processes increasingly depend on third-party digital assets, attackers are evolving to target creators, leveraging social engineering and supply chain weaknesses.

Why This Matters Now

Supply chain risks are rising rapidly as attackers exploit less-obvious channels like 3D asset marketplaces to propagate advanced data stealers. With the creative sector driving innovation and value for many organizations, there is increased urgency to secure digital content workflows and scrutinize external assets for hidden threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Threat actors embedded malicious code within .blend files shared on CGTrader and similar marketplaces; opening these files executed StealC V2 on victims' machines.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust Network Segmentation, egress control, threat detection, and encrypted traffic inspection would have disrupted attacker movement, C2, and exfiltration, limiting the scope and severity of the StealC V2 campaign. Distributed policy enforcement and deep visibility into east-west and outbound traffic would reduce dwell time and data loss, even if initial compromise occurred.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Rapid detection, alerting, and response to anomalous file execution or suspicious process behavior.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limited available attack surface and blocked privilege escalation through strict policy enforcement.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocked unauthorized workload-to-workload and service-to-service movement by malicious actors.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detection and blocking of known malicious C2 traffic and exploit payloads in real-time.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevented or contained unauthorized data transfers to unapproved destinations.

Impact (Mitigations)

Full situational awareness and rapid investigation of suspicious activities across distributed cloud resources.

Impact at a Glance

Affected Business Functions

  • 3D Modeling
  • Animation
  • Game Development
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive data including browser credentials, cryptocurrency wallet information, and personal communications due to the StealC V2 malware.

Recommended Actions

  • Deploy zero trust segmentation and microsegmentation to restrict lateral movement from compromised endpoints.
  • Enforce robust egress security policies to block unauthorized outbound data transfers and command-and-control channels.
  • Integrate inline intrusion prevention systems to detect and halt known malware payloads, including encrypted threat traffic.
  • Leverage behavioral baselining and anomaly detection for rapid detection and response to new attack techniques.
  • Enhance centralized visibility and policy management across multicloud and hybrid environments for unified, real-time control.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image