Researchers and incident reports show the Vidar infostealer continuing to mature as a credential- and data-theft platform, with operators rotating backend infrastructure, tightening access to affiliate panels, and masking administration through Tor relays, VPN services, and hosting concentrated in Moldova and Russia. Team Cymru linked the operation to infrastructure including my-odin[.]com and several shifting IP addresses, while newer technical analysis found Vidar using multi-stage PowerShell delivery, process injection, API hooking, scheduled-task persistence, and theft of browser data by intercepting CryptProtectMemory before encryption. The malware targets Windows systems and steals credentials, cookies, autofill data, payment cards, crypto-wallet files, tokens, documents, and screenshots, then exfiltrates the data over encrypted channels.
Campaigns tied to Vidar have used increasingly flexible command-and-control discovery and broad distribution channels. Analysts observed samples resolving C2 details dynamically through public profiles on Faceit, Telegram, and Steam, allowing operators to change infrastructure without rebuilding malware. Separate reporting tied Vidar to YouTube lures promoting cracked software and AI-generated tutorial videos, where victims were redirected to fake download sites that delivered stealer payloads. Earlier activity also showed Vidar deployed ahead of GandCrab ransomware, stealing victim data before downloading the encryptor, underscoring its role as both a standalone infostealer and a precursor for wider financially motivated intrusions.

Pull IOCs and campaign context straight into your stack.
20 events from the most recent confirmed update back to the earliest known activity.
Censys reported that Vidar command-and-control infrastructure could be identified through a recurring TLS certificate distinguished-name pattern, including the subject string "C=XX, ST=NY, L=NY, O=StaticIP, OU=privateIP." At the time of writing, it had observed 22 unique IP addresses tied to a Vidar campaign, mostly on Hetzner-hosted systems in Germany and Finland.
According to an interview with a Vidar representative, the operation released a major update on November 6, 2023 that completely rewrote the malware's code base. The update changed log transmission to file-by-file delivery and improved duplicate detection, runtime, file collection, and modular support for browsers, wallets, and plugins.
By June 2023, unauthenticated file-download attempts on my-odin[.]com had been changed to redirect users to the Vidar affiliate login page. This closed earlier unauthenticated access to files under the /private path.
eSentire's technical analysis reported that Vidar operators used Mastodon and TikTok profile information, in addition to Telegram and Steam, to publish changing C2 IP and port details for malware samples. The report also analyzed newer builder versions and provided IOCs and tradecraft details for the stealer.
In May 2023, Vidar operators began another hosting migration for my-odin[.]com. Reuse of the same SSL certificate exposed the new hosting IP as 185.229.64.137, assigned to S.C. INFOTECH-GRUP S.R.L.
At the end of March 2023, the hosting IP for my-odin[.]com changed from 5.252.179.201 to 5.252.176.49, another MivoCloud SRL address. The server was then administered through new RDP peers rather than direct access.
From mid-March 2023 onward, management access related to Vidar infrastructure was observed over RDP sessions sourced from ProtonVPN relays. Team Cymru assessed this was likely intended to anonymize operator activity by blending into benign traffic.
In early 2023, the hosting IP for my-odin[.]com changed from 186.2.166.15 to 5.252.179.201. Team Cymru reported that little else changed during this move.
CloudSEK reported that since November 2022 it had observed a 200–300% month-on-month increase in YouTube videos spreading stealer malware, including Vidar. The campaigns increasingly used compromised YouTube accounts and obfuscated links to cracked-software lures.
Since August 2022, Vidar operators used my-odin[.]com as the primary domain for affiliate authentication, file sharing, and panel administration. Earlier, files under its /private path could be downloaded without authentication, including a bash script for setting up a new campaign.
AhnLab ASEC reported that a Vidar 49.6 sample accessed the Mastodon profile of user "banda5ker" on noc.social, parsed the string "hello 162.55.213.180 |," and extracted 162.55.213.180 as its real C2 server. The malware then used that server to download DLLs, receive commands, and exfiltrate stolen data, showing operators could rotate C2 by editing the social-media profile.
CERT-UA investigated an intrusion against a Ukrainian organization in which a trojanized "Advanced IP Scanner" installer delivered Vidar, which stole Telegram session data and enabled attackers to obtain VPN configuration files and access the corporate network. CERT-UA said FRwL/Z-Team (UAC-0118) claimed responsibility for the follow-on attack, which involved reconnaissance, Cobalt Strike, Rclone exfiltration, and Somnia malware causing loss of integrity and availability.
A March 2019 malware analysis described Vidar as a distinct information stealer, noting a locale-based kill switch for several CIS locales and documenting its theft of browser data, cryptocurrency wallets, screenshots, Outlook signature content, and ZIP-based exfiltration to its C2. The report also published sample hashes and a YARA rule for detection.
Security researcher Fumik0 first identified the Vidar infostealer in the wild in late 2018. Researchers described it as a distinct fork of the Arkei malware family.
Splunk documented recent Vidar variants reading Azure CLI's azureProfile.json to collect Azure subscription, tenant, and environment metadata that could support cloud reconnaissance and account takeover. The report also described Vidar loading legitimate Mozilla NSS libraries, including nss3.dll and mozglue.dll, to decrypt browser credentials from unexpected process contexts.
Aryaka Threat Research Lab analyzed a Vidar variant that used a multi-stage PowerShell infection chain, API hooking of CryptProtectMemory, and TLS-encrypted exfiltration. The report identified Telegram and Steam profiles as dead-drop resolver sources and tl.dr.softlinko.com as a C2 server.
CloudSEK reported that threat actors were increasingly using AI-generated presenters from platforms such as Synthesia and D-ID in YouTube videos advertising cracked software to spread stealers including Vidar. The firm also said attackers were uploading multiple malicious videos immediately after taking over YouTube accounts.
Cyble Research & Intelligence Labs identified mass phishing campaigns using YouTube videos and fake software-download sites to distribute Vidar and RecordBreaker stealers. The Vidar activity included phishing sites such as teensoft[.]org and wh1tesoftware[.]me posing as sources for cracked software.
AhnLab ASEC reported a Vidar sample that queried the Faceit API for the profile of user "sslamlssa" and parsed the profile's about field to recover its real C2 URL, 188.34.193.205. The sample then used the resolved server to download DLLs, receive commands, and exfiltrate stolen data.
Cybercriminals distributing GandCrab were observed deploying Vidar first to steal sensitive data before encrypting victims' files. Malwarebytes linked the activity to a malvertising campaign using a rogue ad domain and the Fallout Exploit Kit.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 62 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
18 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourcearyaka.com
Open sourcegatewatcher.com
Open sourcebleepingcomputer.com
Open sourcefumik0.com
Open sourcecisa.gov
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.