Researchers analyzing multiple Vidar Stealer samples found the malware relies heavily on encrypted or XOR-obfuscated strings and dynamic API resolution to conceal its behavior. Reverse engineering with Ghidra and x32dbg exposed decrypted strings tied to LoadLibraryA, GetProcAddress, VirtualAlloc, anti-analysis checks, and broad data-theft functions. The recovered functionality shows Vidar harvesting browser passwords, cookies, autofill data, credit cards, Firefox/NSS secrets, FileZilla and WinSCP data, Steam files, Discord and Telegram artifacts, screenshots, host metadata, and numerous desktop and browser-extension cryptocurrency wallets.
A separate campaign analysis showed Vidar configured to treat some stolen data differently when credentials were associated with hostnames linked to government, military, police, intelligence, CERT, and NATO-related organizations in Poland and the Baltic region. In that sample, the malware decrypted a hardcoded hostname list, checked stolen credentials for matches, and redirected matching data to an alternate command-and-control path, while command-and-control addresses were retrieved from Mastodon profiles including @oleg98 and @artemida. The reporting also linked the broader activity to infrastructure or samples associated with Raccoon, RedLine Stealer, SmokeLoader, and STOP ransomware, indicating a wider criminal ecosystem around the campaign.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
An analysis of a Vidar sample from MalwareBazaar showed how to identify a heavily reused decryption routine in Ghidra and capture encoded and decoded strings dynamically in x32dbg. The recovered strings included anti-analysis markers such as HAL9TH and JohnDoe, Windows API names, and wallet, browser-cookie, and credit-card theft terms that clarified the malware's behavior.
A reverse-engineering note described a VidarStealer sample with an XOR-based string decryption routine and dynamic API resolution via LoadLibraryA and GetProcAddress. Decoded strings revealed theft capabilities spanning browser credentials, cookies, autofill and credit cards, Firefox/NSS secrets, FileZilla, WinSCP, Telegram, Discord, Steam, screenshots, host reconnaissance, and numerous cryptocurrency wallets and extensions.
CERT Polska analyzed a Vidar Stealer sample that decrypted hostnames tied to Polish, Baltic, and NATO-affiliated government, military, intelligence, police, and CERT organizations, then used a flag to route matching stolen credentials to an alternate C2 server. The report also documented Mastodon-based C2 discovery using profiles such as @oleg98 and @artemida and linked the configuration to related malware samples in MWDB.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 45 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourceembee-research.ghost.io
Open sourcekienmanowar.wordpress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.