Info Stealer

Vidar Stealer

First seen: 2018-12 • Status: active

Currently Active Threat

Vidar is a steal-everything malware that criminals customize like ordering from a menu. They choose exactly what to steal - passwords, crypto, files, screenshots. It's cheap to rent and often used as the first step before a bigger attack like ransomware. It hides in fake software downloads and email attachments.

Overview

Vidar is an information-stealing malware that evolved from the Arkei stealer. It is sold as Malware-as-a-Service on Russian-speaking forums and is known for its modular design that allows operators to customize what data to steal. Vidar is frequently used as a first-stage payload before ransomware deployment.

Also Known As

Vidar, Vidar Infostealer

How It Spreads

  • Malicious email attachments (especially ISO and Office files)
  • Fake software download sites
  • SEO poisoning campaigns
  • Compromised software supply chains
  • Malicious ads on search engines

What It Does

  • Steals credentials from 60+ applications
  • Captures browser cookies and session data
  • Extracts 2FA authenticator secrets
  • Steals cryptocurrency wallets and extensions
  • Downloads configuration from C2 specifying targets
  • Self-destructs after exfiltration to avoid detection

Is your business exposed?

Target Platforms

Windows 7, Windows 10, Windows 11

Detection Tips

  • Monitor for processes accessing 2FA application data
  • Alert on executables self-deleting after network activity
  • Detect unusual DLL sideloading in temp directories
  • Watch for connections to Steam profile pages (C2 technique)
  • Monitor browser extension directory access

MITRE ATT&CK Techniques

T1555, T1539, T1552, T1070.004, T1140

If You're Infected

  1. 1.

    Isolate infected endpoint immediately

  2. 2.

    Reset 2FA tokens on all accounts

  3. 3.

    Invalidate all browser sessions and cookies

  4. 4.

    Change all passwords, prioritizing financial accounts

  5. 5.

    Monitor for ransomware deployment (common follow-up)

  6. 6.

    Full system wipe and reinstall recommended

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required