logo

Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection

ID: a278705a-9d91-5668-be28-ad366c50602b

STIX ID: report--a278705a-9d91-5668-be28-ad366c50602b

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-27

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Point Wild researchers analyzed a 2026 Vidar infostealer variant that employs a Go dropper, VBScript and obfuscated PowerShell to retrieve staged payloads concealed inside JPEG and TXT files (Base64 steganography and reversed/obfuscated content), decodes and loads them in memory (.NET assembly and a crypter-protected C++ executable), and actively targets over 200 browser extensions including crypto wallets and password managers; distribution uses fake GitHub/Discord/Reddit repositories, compromised WordPress and fake CAPTCHA pages, and recommended mitigations include blocking direct IP HTTP endpoints, monitoring WScript/PowerShell spawn chains, restricting RegAsm.exe, and auditing startup folders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.