Researchers reported that updated Vidar infostealer campaigns are using steganography, fileless execution, and social-engineering lures to evade detection and steal corporate and consumer data. Point Wild and Intrinsec found infections delivered through fake GitHub repositories, compromised WordPress sites showing ClickFix-style fake CAPTCHA prompts, gaming cheat posts on Reddit and Discord, and bogus software promoted in YouTube videos and hosted on services such as Mediafire. In one chain, a fake tool named NeoHub dropped a malicious DLL disguised as a Microsoft Edge component and signed with counterfeit certificates impersonating GitHub and grow.com.
The malware uses VBScript, obfuscated PowerShell, a Go-based loader, and trusted Windows binaries including WScript, PowerShell, and RegAsm.exe to fetch apparently harmless JPEG and TXT files that contain hidden Base64-encoded second-stage payloads, then reconstructs and executes them entirely in memory through .NET reflective loading. Researchers said Vidar now operates as a Malware-as-a-Service offering, uses Telegram and Dead Drop Resolver techniques via public Steam profiles to locate command-and-control infrastructure, and exfiltrates credentials, cookies, payment data, cryptocurrency wallet files, and information from more than 200 browser extensions, often through Telegram and Cloudflare-fronted domains to mask attacker activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
LevelBlue researchers reported a multi-stage Vidar campaign using a fake software activation tool, MicrosoftToolkit.exe, to deliver the infostealer. The chain used renamed scripts, staged payload extraction, an AutoIt-compiled loader, anti-analysis checks, and post-execution cleanup, while Vidar stole browser credentials, cookies, cryptocurrency wallet files, and system data.
Point Wild's Lat61 Threat Intelligence Team analyzed the 2026 variant and found it used VBScript, obfuscated PowerShell, a Go-based loader, RegAsm.exe, and .NET reflective loading for in-memory execution. The approach minimized disk artifacts and helped the malware evade detection while stealing credentials, wallet data, and browser-extension secrets.
Researchers reported a 2026 campaign distributing Vidar through fake GitHub repositories, gaming cheat lures shared on Discord and Reddit, and ClickFix-style fake CAPTCHA pages on compromised WordPress sites. These social-engineering vectors were used to trigger the malware's staged execution chain.
In 2026, researchers identified a Vidar variant that concealed Base64-encoded second-stage payload data inside seemingly benign JPEG and TXT files. The files were retrieved during a multi-stage infection chain and used to reconstruct the payload while reducing obvious malicious artifacts.
Intrinsec documented an infection chain in which Vidar used a malicious DLL disguised as a Microsoft Edge component and signed with counterfeit certificates impersonating GitHub and grow.com. The malware used a Dead Drop Resolver via public Steam profiles and Telegram channels to locate command-and-control infrastructure dynamically.
In early 2026, a Vidar campaign targeted corporate employees with fake software downloads advertised in YouTube videos and hosted on file-sharing services such as Mediafire. One documented lure used a fake tool called NeoHub to deliver the malware.
In October 2025, Vidar 2.0 was released, adding improved capabilities and stronger evasion. Subsequent reporting says it became one of the top stealers sold on Russian Market.
Law enforcement actions in 2025 disrupted the Lumma and Rhadamanthys infostealer ecosystems. Reporting says Vidar's rise accelerated afterward as operators and buyers shifted toward alternative stealers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcecybersecuritynews.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcepointwild.com
Open sourceacronis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.