A financially motivated malware campaign used malvertising and fake cracked-software downloads to infect consumer and SMB victims worldwide with Vidar Stealer and the XMRig Monero miner. Researchers said the operation, active in April 2026 and aimed primarily at victims in the U.S. and European Union, relied on Go-based loaders built with Factory-v3, fake code-signing certificates impersonating JustWatch and later Bleacher Report, and oversized binaries padded with null bytes to hinder detection and analysis.
After execution, the malware used persistence mechanisms, DLL sideloading variants, and an AMSI bypass before dropping Vidar and XMRig payloads. The stealer exfiltrated credentials, browser cookies, and cryptocurrency wallet data to attacker-controlled infrastructure, while the miner generated Monero and alerted operators through Telegram messages labeled "X3D MINER • NEW LOG". Researchers assessed the operator as a Vidar malware-as-a-service affiliate and noted the same Factory-v3 service also supported a concurrent Lumma Stealer campaign.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
In April 2026, a financially motivated malware campaign used malvertising and fake cracked-software downloads to infect consumer and SMB victims worldwide with Vidar stealer and the XMRig Monero miner. Unit 42 assessed the operator as a Vidar MaaS affiliate primarily targeting victims in the U.S. and European Union.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 111 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcecommunity.gurucul.com
Open sourcedarkreading.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.