typeentityconfidencemediumcreated2026-08-04updated2026-08-04malware-familyinfostealerpython-pyinstallerc2exfiltrationdefense-evasionsigningmitre-attck

BlankGrabber

Overview

BlankGrabber is an open-source Python infostealer distributed as a PyInstaller single-file PE. The builder is publicly available and widely forked, producing commodity grabber variants targeting browser credentials, cryptocurrency wallets, Discord tokens, session cookies, system information, and screenshots. Exfiltration is typically via operator-configured Discord webhook or Telegram Bot API. The builder supports optional anti-VM, anti-debug, and AES payload encryption.

Build Stack

  • Language: Python 3.x (observed: 3.14 in sample f9a13ee9)
  • Packer: PyInstaller single-file PE64+ with embedded PKG archive
  • Compiler: MinGW-w64 GCC (observed: 15.2.0)
  • Signing: Frequently signed with valid Sectigo EV or other commercial code-signing certificates; also observed unsigned ^[/intel/analyses/f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24.html]
  • Masquerade: Often uses Microsoft-themed version info (NewDev.EXE, driver-installer descriptions) ^[/intel/analyses/f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24.html]

Deploy / TTPs

  • Credential Theft: Chromium/Firefox/Edge/Opera/Brave Login Data, Cookies, Web Data, Local State via DPAPI + AES ^[browser-credential-harvesting]
  • Wallet Targets: Exodus, MetaMask, Atomic, Trust Wallet, Coinbase, Binance, Ledger Live, Trezor, Electrum, Monero (typical builder options)
  • Discord Token Exfil: Discord client Local Storage/leveldb token extraction
  • System Recon: WMI queries (Win32_OperatingSystem, Win32_ComputerSystem, Win32_Processor), public IP via api.ipify.org or similar
  • Exfiltration: Discord webhook (discord.com/api/webhooks/...) or Telegram Bot API (api.telegram.org/bot<token>/sendDocument)
  • Anti-Analysis: Optional builder-side anti-VM (WMI Win32_ComputerSystem model checks), anti-debug (IsDebuggerPresent), and screenshot capture
  • Persistence: Optional registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) set by builder

Capabilities

  • credential-dumping-browser-storage
  • discord-webhook-c2-exfiltration
  • telegram-bot-c2-exfiltration
  • wallet-seed-cryptocurrency-theft
  • screenshot-capture
  • clipboard-hijack
  • systeminfo-harvesting-wmi
  • registry-run-persistence
  • anti-vm-wmi-model-check
  • aes-encrypted-payload-extraction
  • version-info-masquerade

Variants / Aliases

  • Builder forks on GitHub: Blank-Grabber, BlankGrabber, Blank Grabber v2, Blank Grabber v3
  • Often re-branded by script kiddies with changed webhook URLs and icon resources

Notable Analyses

  • f9a13ee9 — Python 3.14 PyInstaller build, Sectigo EV-signed, NewDev.EXE masquerade, May 2026 ^[/intel/analyses/f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24.html]

Related Entities