Vidar is a Windows information stealer used to collect browser-stored credentials, cookies, and other locally stored authentication data from compromised systems. Stolen browser cookies can enable session hijacking, including takeover of web and AI-service accounts without repeating password or multifactor-authentication checks. Vidar has been identified in incidents involving theft of authenticated Claude sessions and credentials. It has also been observed as a final payload in multi-stage malware operations and, in a Go-based variant, downloading and executing additional malware stages. Observed delivery includes targeted phishing campaigns using impersonated document-service lures; Vidar has also appeared in malicious-software and traffic-distribution chains. No specific threat actor attribution is established by the available evidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC7005 distributes information-stealing malware. The group deploys VIDAR for Windows ... disguised as conference companion applications.
In a broader campaign in late May 2026, attackers used a fake Ukraine-related summit site to distribute browser-information stealers to Windows and macOS users. Windows visitors received VIDAR...
It was also discovered that in early 2020, before distributing the Raccoon stealer, the attackers had distributed samples of another stealer called Vidar.
Today, we will discuss one of the more advanced stealers: Vidar. Vidar is a piece of malware originating from the Arkei Stealer but uses new methods to find and direct traffic to the attacker.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
We found an interesting connections log from May 2019. The sample was related to the Vidar stealer malware family... we can conclude that the Vidar campaign and the DeathRansom campaign are run by the same actor.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
“Further analysis revealed classic packing techniques, indicating that additional obfuscation layers are applied to hinder reverse engineering.”
“The phishing page closely mimics the original DocuSign site in appearance” and the delivered file is named “DocuSign_PackageInstaller.exe.”
« ... puis utilise ces sessions pour accéder aux comptes Claude et épuiser leur quota d’utilisation. »
STEALC calls ReadProcessMemory to access CanonicalCookieChrome structures from the Chrome network-service process. LUMMA uses NtReadVirtualMemory to locate chrome.dll and dump cookies in clear text.
Infostealers implement bypasses around Chrome Application-Bound Encryption to retrieve cookie data; STEALC, METASTEALER, PHEMEDRONE, XENOSTEALER, and LUMMA recover cookies in plaintext.
STEALC uses CreateToolhelp32Snapshot to scan and terminate all chrome.exe processes, then enumerates Chrome child processes for the --utility-sub-type=network.mojom.NetworkService flag.
1,030 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer capable of harvesting credentials, session tokens, and API keys from compromised systems; the stolen data may be packaged as stealer logs and sold to enable unauthorized access to AI services.
An information-stealer malware cited as likely capable of stealing AI developer configuration credentials.
Named only as an alternative malware payload distributed to Windows visitors by traffic-distribution systems; it is not the subject of this reference.
Named only as a Windows-targeting payload distributed through traffic-routing chains; no further details are provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.