A phishing campaign distributed the Vidar infostealer through .ISO attachments containing malicious Microsoft Compiled HTML Help (.CHM) files and a payload disguised as a Word document. Researchers said the infection chain used several nested stages to obscure execution—moving from ISO to CHM to HTA/JavaScript and finally to an executable—while making the lure appear benign to users. In observed samples, a file such as pss10r.chm silently relaunched through mshta and executed app.exe, which was identified as Vidar.
The malware used Vidar version 50.3 and retrieved command-and-control directions from Mastodon profile bios before downloading configuration data from C2 servers. Once active, it collected system information, browser and application passwords, and other sensitive data including payment details and cryptocurrency wallets, then exfiltrated the information in a ZIP archive. Researchers also reported that Vidar could download additional malware and remove created files afterward to reduce forensic evidence, underscoring the campaign's focus on stealth and credential theft.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Trustwave said there was a notable increase in attackers using ISO files as malware containers beginning in 2019. This provides context for the delivery method used in the Vidar campaign.
The references state that Vidar was first seen in the wild in late 2018. It is described as a commercially sold infostealer and a variant of the earlier Arkei malware family.
The campaign analysis showed Vidar version 50.3 retrieving command-and-control directions from Mastodon profiles, then downloading configuration from C2 servers. Researchers also described how the CHM file was largely legitimate content with appended code that silently launched the malware.
Trustwave SpiderLabs reported a phishing/email campaign distributing the Vidar infostealer through an ISO attachment containing a malicious CHM help file disguised alongside a fake document. The infection chain used nested stages including CHM, HTA/JavaScript, and an executable payload to obscure execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcethreatpost.com
Open sourcetrustwave.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.