Threats Tagged 'vidar'
View all threats tagged with 'vidar'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vidar'
Click on any threat for detailed analysis and mitigation recommendations
Vidar is an information-stealing malware first identified in 2018 that has progressively enhanced its string obfuscation methods to avoid detection and analysis. From May to September 2026, it evolved from simple XOR encryption to using ChaCha20-based algorithms and then implemented a custom virtual machine (VM) with a lightweight bytecode interpreter and custom stream ciphers that vary per build. The VM uses 14 opcode handlers with basic operations such as XOR, addition, rotation, and substitution. Version 2.0 introduced the VM, and versions 2.2 and later added ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants. These per-build changes in opcodes, constants, and substitution tables complicate static and automated analysis efforts. Join the discussion | AlienVault OTX General | 09/21/2026, 16:45:51 UTC Added: 09/22/2026, 08:02:57 UTC |
VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations. Join the discussion | AlienVault OTX General | 09/16/2026, 17:03:00 UTC Added: 09/17/2026, 10:46:37 UTC |
This analysis examines a sophisticated Vidar infostealer variant that employs a custom virtual machine to obfuscate its malicious code through proprietary bytecode interpretation. The malware implements extensive anti-analysis measures including debugger detection via NtQueryInformationProcess and RDTSC timing checks, sandbox evasion by identifying antivirus processes and checking system resources, and environment fingerprinting. Vidar targets credentials from web browsers including Chromium and Gecko-based extensions, Azure authentication tokens, FileZilla FTP credentials, and captures screenshots. It utilizes SeDebugPrivilege for elevated access, creates hidden desktops for browser automation, and exfiltrates stolen data through Telegram channels. The malware performs cleanup operations to remove execution artifacts and proxies DLL execution through rundll32.exe to blend with legitimate Windows processes. Join the discussion | AlienVault OTX General | 09/09/2026, 06:38:56 UTC Added: 09/09/2026, 10:51:59 UTC |
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands. MediumMalware Join the discussion | AlienVault OTX General | 09/08/2026, 12:29:01 UTC Added: 09/09/2026, 09:22:16 UTC |
Cybercriminals are exploiting the hype around Grand Theft Auto VI by creating fake websites that impersonate official Rockstar Games promotional material. These sites offer a GTA 6 demo download which is actually a Vidar infostealer malware. The malware steals sensitive browser data including passwords, cookies, session tokens, autofill data, and FTP credentials from multiple browsers. It uses legitimate browser binaries in headless mode to bypass protections and steal data more effectively. Stolen session tokens can bypass two-factor authentication, allowing persistent unauthorized access even after password changes. This campaign leverages recent GTA 6 leaks to lure victims. Join the discussion | AlienVault OTX General | 08/25/2026, 07:10:28 UTC Added: 08/25/2026, 10:52:01 UTC |
Three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—target individuals in academia, aerospace, defense, governments, and think tanks in Europe and the US. They use sophisticated phishing techniques including app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are linked with moderate confidence to ICE RELIC (APT29), while UNC5976 is distinct. Their operations involve social engineering tactics such as fake diplomatic invitations and conference registrations. They abuse legitimate authentication mechanisms like Google OAuth and Microsoft device codes, complicating detection. Join the discussion | AlienVault OTX General | 08/20/2026, 17:09:14 UTC Added: 08/20/2026, 23:22:26 UTC |
WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims... Join the discussion | CVE Database V5 | 08/11/2026, 15:30:01 UTC Added: 06/16/2026, 20:46:48 UTC |
TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through CLICKFIX-VIDAR infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying VIDAR as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service. Join the discussion | AlienVault OTX General | 07/16/2026, 02:29:55 UTC Added: 07/16/2026, 10:32:46 UTC |
During June 2026, multiple infostealer families including Remus, ACRStealer, LummaC2, and Vidar were distributed through SEO poisoning techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and DLL side-loading (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through ClickFix techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed AgentTesla and DarkCloud through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks. Join the discussion | AlienVault OTX General | 07/15/2026, 11:58:14 UTC Added: 07/15/2026, 21:47:49 UTC |
Vidar, a Malware-as-a-Service infostealer first identified in 2018, continues to be distributed through phishing campaigns targeting Korea in the first half of 2026. The threat actor uses phishing emails disguised as job applications and copyright infringement notices, with attachments appearing as Word documents but actually being executables. Vidar employs a Go-based packer, uses Dead Drop Resolver technique via Telegram and Steam profiles to obtain C&C addresses, and implements anti-debugging and anti-VM techniques. The infostealer exfiltrates sensitive information including browser credentials, cookies, browsing history, cryptocurrency wallet data, Discord tokens, Telegram information, Steam data, Azure credentials, and screenshots. Configuration information is downloaded in JSON format, and data collection is performed based on received flags and additional downloaded conditions. Join the discussion | AlienVault OTX General | 07/09/2026, 11:27:51 UTC Added: 07/09/2026, 13:04:37 UTC |
Showing 1 to 10 of 35 results