Vidar 2.0 is an information-stealing malware family referenced as one of the more popular infostealers in the cybercriminal ecosystem. The provided reporting states that it has been distributed via fake game cheats hosted or promoted on GitHub and Reddit, and that it is also delivered in JackFix campaigns, where heavily obfuscated PowerShell payloads download multiple commercial infostealers and loaders, including Vidar 2.0. Recent reporting in the supplied content says Vidar 2.0 has shifted from primarily targeting consumer browser credentials to targeting enterprise cloud credentials and authentication keys, including credentials cached on unmanaged or BYOD devices, increasing organizational risk. The content does not attribute Vidar 2.0 itself to a specific threat actor, but it notes use by Russian-speaking cybercriminals in the context of JackFix delivery activity. High-confidence capabilities directly mentioned in the content are credential theft and theft of authentication material; no specific IOCs are provided in the supplied material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence is then established through a scheduled task named “SystemBackgroundUpdate”, configured to run at user logon with elevated privileges.
Analysis revealed that these executables are PowerShell scripts compiled into .NET binaries using the open-source PS2EXE module.
Persistence is then established through a scheduled task named “SystemBackgroundUpdate”, configured to run at user logon with elevated privileges.
The malware also employs an advanced technique that launches browsers with debugging enabled and injects malicious code directly into running browser processes using either shellcode or reflective DLL injection.
Binary analysis reveals that the new version of Vidar employs heavy use of control flow flattening, implementing complex switch-case structures with numeric state machines that can make reverse engineering more difficult.
The downloaded payload (background.exe) is a Themida-packed Vidar stealer 2.0.
The malware also employs an advanced technique that launches browsers with debugging enabled and injects malicious code directly into running browser processes using either shellcode or reflective DLL injection.
The malware also employs an advanced technique that launches browsers with debugging enabled and injects malicious code directly into running browser processes using either shellcode or reflective DLL injection.
The malware also employs an advanced technique that launches browsers with debugging enabled and injects malicious code directly into running browser processes using either shellcode or reflective DLL injection.
It adds a Windows Defender exclusion for a specified attacker-controlled directory... create a randomly named directory inside the %AppData% directory, adds it to Defender’s exclusion list
It is executed as a background process and attempts to elevate its privileges using “runas”.
Extensive anti-analysis checks, including debugger detection, timing checks, uptime, and hardware profiling.
The malware then performs extensive anti-analysis checks including debugger detection, timing verification, system uptime validation, and hardware profiling to ensure execution only occurs on genuine victim systems rather than analysis environments.
it verifies the file by checking the MZ header and sets both the directory and file attributes to “hidden” so that it’s not visible to users.
Vidar 2.0 malware has specific logic to enumerate the %USERPROFILE%\.azure directory, using it to extract Azure credentials and exfiltrate the data back to the attackers.
Infostealers scan developer environments for files like credentials.json or .env files that store active OpenAI API keys in plaintext.
Among its traditional credential extraction techniques, the malware employs a tiered approach that includes systematic enumeration of browser profiles and attempting to extract encryption keys from Local State files using standard DPAPI decryption.
Binary analysis reveals that Vidar 2.0 implements comprehensive browser credential extraction capabilities targeting both traditional browser storage methods and Chrome's latest security protections across multiple browser platforms including Chrome, Firefox, Edge, and other Chromium-based browsers.
Following successful evasion, the malware conducts thorough system profiling to collect victim information before launching parallel credential theft operations across multiple categories.
The file grabber component systematically searches for valuable files across user directories and removable drives, focusing on cryptocurrency keys and potential credential files.
MITRE ATT&CK Matrix Tactic Technique ID Technique Name ... T1087.001 Account Discovery: Local Account
Extensive anti-analysis checks, including debugger detection, timing checks, uptime, and hardware profiling.
The malware then performs extensive anti-analysis checks including debugger detection, timing verification, system uptime validation, and hardware profiling to ensure execution only occurs on genuine victim systems rather than analysis environments.
The final phases involve screenshot capture for additional intelligence value, followed by comprehensive data packaging and exfiltration through HTTP multipart form submissions to a round-robin command-and-control (C&C) infrastructure
The final phases involve screenshot capture for additional intelligence value, followed by comprehensive data packaging and exfiltration through HTTP multipart form submissions to a round-robin command-and-control (C&C) infrastructure that includes Telegram bots and Steam profiles as communication channels.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware spread via fake game cheats on GitHub and Reddit.
Evolved infostealer variant described as shifting from consumer browser credential theft to enterprise-focused theft of cloud credentials and authentication keys, particularly from unmanaged/BYOD endpoints—enabling access to corporate cloud infrastructure outside traditional endpoint control visibility.
Vidar 2.0 is an updated version of the Vidar infostealer, designed to exfiltrate credentials and other sensitive data from victims. It is deployed as part of the JackFix attack payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.