Vidar Stealer is a Windows information-stealing malware family derived from the Arkei codebase and active since late 2018. It is widely operated as a malware-as-a-service offering and remains one of the most prevalent commodity stealers in criminal ecosystems. Vidar is primarily used to harvest sensitive data from infected hosts, especially browser-stored credentials, cookies, autofill data, payment information, cryptocurrency wallet material, and other locally accessible secrets. Stolen session cookies and tokens can enable downstream account compromise without requiring the victim’s password, making Vidar a frequent enabler of cloud and SaaS intrusions.
Vidar commonly targets Chromium-based browsers and has also been reported to collect Tor Browser data and two-factor authentication-related information. In addition to credential theft, some campaigns use Vidar as an intermediate delivery component that retrieves and launches secondary malware, giving it both stealer and loader roles in practice. Recent observed chains used a Go-based Vidar stage to fetch follow-on payloads such as TELEPUZ, which then expanded the intrusion with persistence, remote command execution, and additional theft modules.
Distribution has been observed through multiple social-engineering and malware-delivery channels, including malvertising, fake cracked-software downloads, trojanized code repositories, spam or phishing attachments, malicious packages, and ClickFix-style lures that trick users into executing attacker-supplied commands. Vidar has also been associated with script-based delivery chains and in-memory execution techniques intended to reduce forensic visibility. Some campaigns have paired it with other malware families or auxiliary payloads, including cryptominers, and have used DLL sideloading as part of execution.
Vidar is frequently referenced in stealer-log and initial-access ecosystems because credentials and session material harvested by the malware are resold or reused for follow-on compromise. Reported downstream abuse includes breaches of enterprise cloud file-sharing and collaboration platforms using credentials originally stolen by Vidar and other commodity stealers. The malware is broadly opportunistic rather than sector-specific, but its impact extends across consumer and enterprise environments wherever browser-stored secrets, wallet data, or authenticated sessions are present.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The observed campaigns led to collection of payment card data, theft of credentials and access tokens, and delivery of malware including Vidar Stealer, Lumma Stealer, Hijack Loader, and Oyster.
The observed campaigns led to collection of payment card data, theft of credentials and access tokens, and delivery of malware including Vidar Stealer, Lumma Stealer, Hijack Loader, and Oyster.
UNC5142 (ClearFake Cluster): Primarily uses the BNB Smart Chain to distribute infostealers such as LUMMAC.V2 and Vidar via compromised WordPress sites.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Since at least early 2026, Microsoft observed malvertising campaigns using AI-themed terms such as “ Awesome AI Windows Plugin ” and “ Flux Pro AI ” in popup lures, malware filenames, and GitHub repository paths.
In our case, the attacker entered the network over VPN (Username: Nexus, Password: Nexus123 - no MFA. Local admin.
This includes both legitimate administrative scripts and potentially malicious commands.
ScriptBlock Smuggling allows an attacker to spoof any arbitrary message into the ScriptBlock logs while bypassing AMSI.
after launch, it displayed a “Continue” checkbox, then dropped pythonw.exe and LICENSE.txt into *\AppData\Local*, executed shellcode, contacted brokeapt[.]com, and delivered Vidar infostealer.
The initial code should, therefore, still be obfuscated to such an extent that it’s not trivial for a monitoring solution to detect the malicious smuggling code.
with payloads embedded in JPEG and TXT files for in-memory execution... retrieves a Base64-encoded DLL appended to a JPEG hosted on public image services
This Smuggling attack would only trick the logging in the Script Block Log, EventID 4104.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
Potential impacts include payment card theft, credential compromise, AiTM-based session hijacking, infostealer infections (e.g., Vidar), account takeover, unauthorized access to government and financial services, data leakage, malware propagation, and reputational damage through the misuse of compromised accounts.
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
Vidar est un malware de type infostealer conçu pour exfiltrer des données sensibles, notamment des identifiants (bancaires, connexion…) ainsi que des informations liées à la navigation des victimes.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
Il se distingue par son mode de communication avec son serveur de commande et de contrôle (C2), dont l’adresse est obtenue de manière indirecte via des plateformes légitimes ou des réseaux sociaux tels que Telegram ou Steam.
590 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison point for browser credential theft methods similar to those used by Vanta Stealer.
Referenced as another infostealer family co-delivered alongside Remus via shared infrastructure.
The campaign also leverages shared malware distribution infrastructure hosting multiple infostealer families.
Arkei-based malware-as-a-service information stealer that harvests browser credentials, cookies, two-factor authentication data, Tor Browser configurations, and cryptocurrency wallets. Recent campaigns used malvertising, fake cracked-software downloads, trojanized GitHub repositories, and payloads embedded in JPEG/TXT files for in-memory execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.