Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation
Vidar is an information-stealing malware first identified in 2018 that has progressively enhanced its string obfuscation methods to avoid detection and analysis. From May to September 2026, it evolved from simple XOR encryption to using ChaCha20-based algorithms and then implemented a custom virtual machine (VM) with a lightweight bytecode interpreter and custom stream ciphers that vary per build. The VM uses 14 opcode handlers with basic operations such as XOR, addition, rotation, and substitution. Version 2.0 introduced the VM, and versions 2.2 and later added ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants. These per-build changes in opcodes, constants, and substitution tables complicate static and automated analysis efforts.
AI Analysis
Technical Summary
Vidar is an information stealer malware that has continuously evolved its string obfuscation techniques to evade detection. Initially using basic XOR encryption, it progressed to ChaCha20-based algorithms and recently implemented a custom virtual machine executed via a lightweight bytecode interpreter. This VM includes 14 opcode handlers with simple primitives like XOR, addition, rotation, and substitution. Starting with version 2.0, the VM approach was introduced, and from version 2.2 onwards, ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants were added. These per-build variations in opcode handlers, constants, and substitution tables significantly hinder static and automated analysis capabilities, making detection and reverse engineering more challenging.
Potential Impact
Vidar's advanced string obfuscation techniques, including a custom VM and per-build custom stream ciphers, increase the difficulty of detection and analysis by security tools and researchers. This obfuscation helps the malware evade static and automated detection methods, potentially allowing it to persist longer on infected systems and steal information without being detected. However, there is no indication of active exploitation in the wild or specific targeted countries.
Mitigation Recommendations
No official patch or remediation is available as this is malware behavior rather than a software vulnerability. Mitigation should focus on detection and prevention using updated threat intelligence, behavioral analysis, and endpoint protection solutions capable of identifying Vidar's evolving obfuscation techniques. Analysts should leverage the provided indicators of compromise (hashes) for detection. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.
Indicators of Compromise
- hash: 2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6
- hash: 16addb6524e5cf76f4114b0979f715ff
- hash: 91c3431e51158aa800a452222a2404d7b82631ea
- hash: 37ee3afa9df9c7d65b780cf54e908a98b92c4a5b
- hash: 03f13619a413dd1bd7ff8dd47687b3e9
- hash: 979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4
- hash: a2535f051c329131c107d14651ace793
- hash: eb2a38a90d20475b00bdc285b89eb50eefd0b88e
- hash: 1628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974
- hash: 625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074
Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation
Description
Vidar is an information-stealing malware first identified in 2018 that has progressively enhanced its string obfuscation methods to avoid detection and analysis. From May to September 2026, it evolved from simple XOR encryption to using ChaCha20-based algorithms and then implemented a custom virtual machine (VM) with a lightweight bytecode interpreter and custom stream ciphers that vary per build. The VM uses 14 opcode handlers with basic operations such as XOR, addition, rotation, and substitution. Version 2.0 introduced the VM, and versions 2.2 and later added ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants. These per-build changes in opcodes, constants, and substitution tables complicate static and automated analysis efforts.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Vidar is an information stealer malware that has continuously evolved its string obfuscation techniques to evade detection. Initially using basic XOR encryption, it progressed to ChaCha20-based algorithms and recently implemented a custom virtual machine executed via a lightweight bytecode interpreter. This VM includes 14 opcode handlers with simple primitives like XOR, addition, rotation, and substitution. Starting with version 2.0, the VM approach was introduced, and from version 2.2 onwards, ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants were added. These per-build variations in opcode handlers, constants, and substitution tables significantly hinder static and automated analysis capabilities, making detection and reverse engineering more challenging.
Potential Impact
Vidar's advanced string obfuscation techniques, including a custom VM and per-build custom stream ciphers, increase the difficulty of detection and analysis by security tools and researchers. This obfuscation helps the malware evade static and automated detection methods, potentially allowing it to persist longer on infected systems and steal information without being detected. However, there is no indication of active exploitation in the wild or specific targeted countries.
Defensive Guidance
No official patch or remediation is available as this is malware behavior rather than a software vulnerability. Mitigation should focus on detection and prevention using updated threat intelligence, behavioral analysis, and endpoint protection solutions capable of identifying Vidar's evolving obfuscation techniques. Analysts should leverage the provided indicators of compromise (hashes) for detection. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/vidar-adds-virtual-machine-and-custom-stream-ciphers-string-obfuscation"]
- Pulse Id
- 6ab15f3f1d05b3fb6ae23973
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6 | — | |
hash16addb6524e5cf76f4114b0979f715ff | — | |
hash91c3431e51158aa800a452222a2404d7b82631ea | — | |
hash37ee3afa9df9c7d65b780cf54e908a98b92c4a5b | — | |
hash03f13619a413dd1bd7ff8dd47687b3e9 | — | |
hash979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4 | — | |
hasha2535f051c329131c107d14651ace793 | — | |
hasheb2a38a90d20475b00bdc285b89eb50eefd0b88e | — | |
hash1628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974 | — | |
hash625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074 | — |
Threat ID: 6ab23631f7a7c54106e0318e
Added to database: 09/22/2026, 08:02:57 UTC
Last enriched: 09/22/2026, 08:20:18 UTC
Last updated: 09/22/2026, 15:04:44 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.