Skip to main content

Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation

0
Medium
Published: 09/21/2026 (09/21/2026, 16:45:51 UTC)
Source: AlienVault OTX General

Description

Vidar is an information-stealing malware first identified in 2018 that has progressively enhanced its string obfuscation methods to avoid detection and analysis. From May to September 2026, it evolved from simple XOR encryption to using ChaCha20-based algorithms and then implemented a custom virtual machine (VM) with a lightweight bytecode interpreter and custom stream ciphers that vary per build. The VM uses 14 opcode handlers with basic operations such as XOR, addition, rotation, and substitution. Version 2.0 introduced the VM, and versions 2.2 and later added ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants. These per-build changes in opcodes, constants, and substitution tables complicate static and automated analysis efforts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 08:20:18 UTC

Technical Analysis

Vidar is an information stealer malware that has continuously evolved its string obfuscation techniques to evade detection. Initially using basic XOR encryption, it progressed to ChaCha20-based algorithms and recently implemented a custom virtual machine executed via a lightweight bytecode interpreter. This VM includes 14 opcode handlers with simple primitives like XOR, addition, rotation, and substitution. Starting with version 2.0, the VM approach was introduced, and from version 2.2 onwards, ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants were added. These per-build variations in opcode handlers, constants, and substitution tables significantly hinder static and automated analysis capabilities, making detection and reverse engineering more challenging.

Potential Impact

Vidar's advanced string obfuscation techniques, including a custom VM and per-build custom stream ciphers, increase the difficulty of detection and analysis by security tools and researchers. This obfuscation helps the malware evade static and automated detection methods, potentially allowing it to persist longer on infected systems and steal information without being detected. However, there is no indication of active exploitation in the wild or specific targeted countries.

Defensive Guidance

No official patch or remediation is available as this is malware behavior rather than a software vulnerability. Mitigation should focus on detection and prevention using updated threat intelligence, behavioral analysis, and endpoint protection solutions capable of identifying Vidar's evolving obfuscation techniques. Analysts should leverage the provided indicators of compromise (hashes) for detection. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/vidar-adds-virtual-machine-and-custom-stream-ciphers-string-obfuscation"]
Pulse Id
6ab15f3f1d05b3fb6ae23973

Indicators of Compromise

Hash

ValueDescriptionCopy
hash2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6
hash16addb6524e5cf76f4114b0979f715ff
hash91c3431e51158aa800a452222a2404d7b82631ea
hash37ee3afa9df9c7d65b780cf54e908a98b92c4a5b
hash03f13619a413dd1bd7ff8dd47687b3e9
hash979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4
hasha2535f051c329131c107d14651ace793
hasheb2a38a90d20475b00bdc285b89eb50eefd0b88e
hash1628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974
hash625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074

Threat ID: 6ab23631f7a7c54106e0318e

Added to database: 09/22/2026, 08:02:57 UTC

Last enriched: 09/22/2026, 08:20:18 UTC

Last updated: 09/22/2026, 15:04:44 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses