Threats Tagged 'vidar'
View all threats tagged with 'vidar'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vidar'
Click on any threat for detailed analysis and mitigation recommendations
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains 0 TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through CLICKFIX-VIDAR infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying VIDAR as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service. Join the discussion | AlienVault OTX General | 07/16/2026, 02:29:55 UTC Added: 07/16/2026, 10:32:46 UTC |
June 2026 Infostealer Trend Report 0 During June 2026, multiple infostealer families including Remus, ACRStealer, LummaC2, and Vidar were distributed through SEO poisoning techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and DLL side-loading (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through ClickFix techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed AgentTesla and DarkCloud through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks. Join the discussion | AlienVault OTX General | 07/15/2026, 11:58:14 UTC Added: 07/15/2026, 21:47:49 UTC |
Vidar Infostealer Being Spread through Phishing Emails 0 Vidar, a Malware-as-a-Service infostealer first identified in 2018, continues to be distributed through phishing campaigns targeting Korea in the first half of 2026. The threat actor uses phishing emails disguised as job applications and copyright infringement notices, with attachments appearing as Word documents but actually being executables. Vidar employs a Go-based packer, uses Dead Drop Resolver technique via Telegram and Steam profiles to obtain C&C addresses, and implements anti-debugging and anti-VM techniques. The infostealer exfiltrates sensitive information including browser credentials, cookies, browsing history, cryptocurrency wallet data, Discord tokens, Telegram information, Steam data, Azure credentials, and screenshots. Configuration information is downloaded in JSON format, and data collection is performed based on received flags and additional downloaded conditions. Join the discussion | AlienVault OTX General | 07/09/2026, 11:27:51 UTC Added: 07/09/2026, 13:04:37 UTC |
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation 0 A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking. Join the discussion | AlienVault OTX General | 07/07/2026, 23:19:29 UTC Added: 07/09/2026, 11:32:31 UTC |
Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories 0 A malicious Go module posing as a DNS/subdomain scanner exposed a sophisticated Windows malware staging operation utilizing commit-farming workflows, public dead drops, and protected archives to deploy RAT and infostealer malware. The operation, tracked as 'Muck and Load', leverages a GitHub-based infrastructure comprising 222 confirmed repositories across 190 accounts designed to appear active and legitimate through automated GitHub Actions workflows. The attack chain begins with a deceptive Go module that downloads encoded PowerShell content, which then queries multiple public platforms including Pastebin, Telegram, YouTube, and Instagram as dead drops for encrypted payload locations. The loader retrieves password-protected archives containing AsyncRAT, Quasar, Remcos, and Vidar infostealer payloads, executing them from masqueraded Microsoft-themed directories. At least 14 malware files were confirmed across the repository network. Join the discussion | AlienVault OTX General | 07/09/2026, 08:24:59 UTC Added: 07/09/2026, 11:32:31 UTC |
Showing 1 to 5 of 5 results