logo

Vidar Stealer 2.0 distributed via fake game cheats on GitHub and Reddit

ID: 31b99a44-202a-5ff1-acb6-b918a542d45f

STIX ID: report--31b99a44-202a-5ff1-acb6-b918a542d45f

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-07-24

...
...

Acronis TRU documents widespread campaigns abusing GitHub, Reddit and other channels to distribute Vidar Stealer 2.0 disguised as free game cheats; the report details social-engineering lures, multi-stage PowerShell/AutoIt loaders, Themida-packed Vidar payloads, Telegram/Steam-based C2, extensive exfiltration capabilities (browsers, wallets, Azure tokens, FTP/SSH, social apps), numerous IOCs, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.