Info Stealer
Vidar Stealer
First seen: 2018-12 • Status: active
Currently Active Threat
Vidar is a steal-everything malware that criminals customize like ordering from a menu. They choose exactly what to steal - passwords, crypto, files, screenshots. It's cheap to rent and often used as the first step before a bigger attack like ransomware. It hides in fake software downloads and email attachments.
Overview
Vidar is an information-stealing malware that evolved from the Arkei stealer. It is sold as Malware-as-a-Service on Russian-speaking forums and is known for its modular design that allows operators to customize what data to steal. Vidar is frequently used as a first-stage payload before ransomware deployment.
Also Known As
Vidar, Vidar Infostealer
How It Spreads
- • Malicious email attachments (especially ISO and Office files)
- • Fake software download sites
- • SEO poisoning campaigns
- • Compromised software supply chains
- • Malicious ads on search engines
What It Does
- • Steals credentials from 60+ applications
- • Captures browser cookies and session data
- • Extracts 2FA authenticator secrets
- • Steals cryptocurrency wallets and extensions
- • Downloads configuration from C2 specifying targets
- • Self-destructs after exfiltration to avoid detection
Is your business exposed?
Target Platforms
Windows 7, Windows 10, Windows 11
Detection Tips
- • Monitor for processes accessing 2FA application data
- • Alert on executables self-deleting after network activity
- • Detect unusual DLL sideloading in temp directories
- • Watch for connections to Steam profile pages (C2 technique)
- • Monitor browser extension directory access
MITRE ATT&CK Techniques
T1555, T1539, T1552, T1070.004, T1140
If You're Infected
- 1.
Isolate infected endpoint immediately
- 2.
Reset 2FA tokens on all accounts
- 3.
Invalidate all browser sessions and cookies
- 4.
Change all passwords, prioritizing financial accounts
- 5.
Monitor for ransomware deployment (common follow-up)
- 6.
Full system wipe and reinstall recommended
Related Malware
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required