New Vidar Malware Campaign Uses Fake YouTube Software Downloads to Steal Corporate Credentials
ID: ab2fbf07-8677-5af1-86db-20a851ce67ea
STIX ID: report--ab2fbf07-8677-5af1-86db-20a851ce67ea
Feed Name: cybersecurityNews.com
A credential‑stealing malware named Vidar has emerged as a prominent threat in early 2026, distributed via fake software downloads promoted through YouTube and file‑sharing sites; the campaign uses a staged installer (NeoHub.exe) loading a malicious msedge_elf.dll packed with GO-based protections, fake code-signing certificates, and a Dead Drop Resolver (Steam profiles/Telegram) to locate C2, targets multiple browsers and crypto wallets, and is linked to various threat actors including Scattered Spider with stolen credentials sold on Russian Market.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
