BlankGrabber
Overview
BlankGrabber is an open-source Python infostealer distributed as a PyInstaller single-file PE. The builder is publicly available and widely forked, producing commodity grabber variants targeting browser credentials, cryptocurrency wallets, Discord tokens, session cookies, system information, and screenshots. Exfiltration is typically via operator-configured Discord webhook or Telegram Bot API. The builder supports optional anti-VM, anti-debug, and AES payload encryption.
Build Stack
- Language: Python 3.x (observed: 3.14 in sample
f9a13ee9) - Packer: PyInstaller single-file PE64+ with embedded PKG archive
- Compiler: MinGW-w64 GCC (observed: 15.2.0)
- Signing: Frequently signed with valid Sectigo EV or other commercial code-signing certificates; also observed unsigned ^[/intel/analyses/f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24.html]
- Masquerade: Often uses Microsoft-themed version info (
NewDev.EXE, driver-installer descriptions) ^[/intel/analyses/f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24.html]
Deploy / TTPs
- Credential Theft: Chromium/Firefox/Edge/Opera/Brave
Login Data,Cookies,Web Data,Local Statevia DPAPI + AES ^[browser-credential-harvesting] - Wallet Targets: Exodus, MetaMask, Atomic, Trust Wallet, Coinbase, Binance, Ledger Live, Trezor, Electrum, Monero (typical builder options)
- Discord Token Exfil: Discord client
Local Storage/leveldbtoken extraction - System Recon: WMI queries (
Win32_OperatingSystem,Win32_ComputerSystem,Win32_Processor), public IP viaapi.ipify.orgor similar - Exfiltration: Discord webhook (
discord.com/api/webhooks/...) or Telegram Bot API (api.telegram.org/bot<token>/sendDocument) - Anti-Analysis: Optional builder-side anti-VM (WMI
Win32_ComputerSystemmodel checks), anti-debug (IsDebuggerPresent), and screenshot capture - Persistence: Optional registry Run key (
HKCU\Software\Microsoft\Windows\CurrentVersion\Run) set by builder
Capabilities
credential-dumping-browser-storagediscord-webhook-c2-exfiltrationtelegram-bot-c2-exfiltrationwallet-seed-cryptocurrency-theftscreenshot-captureclipboard-hijacksysteminfo-harvesting-wmiregistry-run-persistenceanti-vm-wmi-model-checkaes-encrypted-payload-extractionversion-info-masquerade
Variants / Aliases
- Builder forks on GitHub:
Blank-Grabber,BlankGrabber,Blank Grabber v2,Blank Grabber v3 - Often re-branded by script kiddies with changed webhook URLs and icon resources
Notable Analyses
f9a13ee9— Python 3.14 PyInstaller build, Sectigo EV-signed,NewDev.EXEmasquerade, May 2026 ^[/intel/analyses/f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24.html]
Related Entities
- pyinstaller-bootloader — PyInstaller C bootloader stub
- python-packed-payload — General pattern for Python-in-PE distribution
- discord-webhook-c2-exfiltration — C2 channel
- telegram-bot-exfiltration — C2 channel
- version-info-masquerade — Social-engineering technique
- browser-credential-harvesting — Cross-family credential theft pattern