Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection
ID: a278705a-9d91-5668-be28-ad366c50602b
STIX ID: report--a278705a-9d91-5668-be28-ad366c50602b
Feed Name: cybersecurityNews.com
Point Wild researchers analyzed a 2026 Vidar infostealer variant that employs a Go dropper, VBScript and obfuscated PowerShell to retrieve staged payloads concealed inside JPEG and TXT files (Base64 steganography and reversed/obfuscated content), decodes and loads them in memory (.NET assembly and a crypter-protected C++ executable), and actively targets over 200 browser extensions including crypto wallets and password managers; distribution uses fake GitHub/Discord/Reddit repositories, compromised WordPress and fake CAPTCHA pages, and recommended mitigations include blocking direct IP HTTP endpoints, monitoring WScript/PowerShell spawn chains, restricting RegAsm.exe, and auditing startup folders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
