#BlankGrabber

Malware/Tool

2025-12-12 • APT-C-26(Lazarus)组织利用WinRAR漏洞部署Blank Grabber木马的技术分析

Blank Grabber is an open-source Python information stealer deployed in a Lazarus-attributed cryptocurrency campaign. A malicious Pharos RAR archive exploited CVE-2025-8088 to place a batch file in the Windows Startup folder; the script downloaded an obfuscated Python loader, which installed persistence and executed Blank Grabber. The configured stealer hid its window, created a mutex, and used Telegram for communications. It targeted Chromium and Firefox browser credentials, cookies, autofill data, Discord and Telegram sessions, gaming sessions, Wi-Fi passwords, and seed phrases or private keys from more than twenty cryptocurrency wallets, including MetaMask, Exodus, Electrum, Phantom, and Binance Wallet.

Tagged Reports

« Back