Vidar Malware Targets Browser Credentials, Cookies, Crypto Wallets, and System Data
ID: 3ae3a2f2-45ff-5ad0-bffc-422f8f6c871d
STIX ID: report--3ae3a2f2-45ff-5ad0-bffc-422f8f6c871d
Feed Name: cybersecurityNews.com
A LevelBlue investigation details a multi-stage Vidar infostealer campaign that begins with a fake activation tool (MicrosoftToolkit.exe) and executes staged payloads (batch scripts and an AutoIt loader) to harvest browser credentials, session cookies, cryptocurrency wallet files, and system data. The actor uses public platforms (Steam, Telegram) and dynamic DNS for C2, includes anti-analysis and thorough cleanup routines to evade detection, and the report provides IoCs and remediation recommendations including isolation, reimaging, credential resets, and MFA enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
