Vidar infostealer versions 2.x and 3.x now use a lightweight bytecode virtual machine (VM) to conceal strings and, in some builds, derive key material for a second decryption stage. First observed in 2018, the malware has evolved from single-byte XOR obfuscation to modified ChaCha-based stream ciphers and VM-driven decryption designed to frustrate reverse engineering and static detection.
The VM uses a sparse 256-entry opcode dispatch table with 14 active handlers, a one-byte accumulator, the preceding output byte, and a build-specific four-byte XOR key. Vidar 2.0 and 2.1 use a modified ChaCha-derived cipher, while version 2.2 onward uses a custom add-rotate-XOR (ARX) stream cipher seeded with VM-decrypted key and nonce data; opcode mappings, constants, substitution tables, cipher seeds, and ARX operations vary by build, limiting the reliability of automated string recovery and static signatures.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
During 2026, Vidar internal version 2.0 and later introduced a lightweight bytecode virtual machine and per-build custom stream ciphers for string protection. The VM can directly decode strings or recover key and nonce material for separately encrypted strings.
Vidar, an information-stealing malware family, was first observed. Early samples used single-byte XOR operations to obfuscate strings.
Vidar version 3.1 samples contained protected browser-discovery, wallet, plugin, grabber, loader-error, HWID-generation, and HTTP Accept-header strings. The samples demonstrate continued use of the VM and stream-cipher string-protection scheme.
Starting with version 2.2, Vidar replaced the modified ChaCha-based cipher with a custom add-rotate-XOR stream cipher. The cipher derives a 32-bit state from VM-decrypted key and nonce material and changes transformations and constants between builds.
Vidar versions 2.0 and 2.1 used VM-decoded key and nonce material with a modified ChaCha-based stream cipher, employing a custom 128-bit initial state, an eight-byte key, and a four-byte nonce.
Beginning with internal version 1.8, Vidar altered its ChaCha20 implementation to make detection and string decryption more difficult.
Vidar adopted ChaCha20-based string encryption beginning with internal version 1.5, replacing its earlier simple XOR string obfuscation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.