logo

New Vidar Malware Campaign Uses Fake YouTube Software Downloads to Steal Corporate Credentials

ID: ab2fbf07-8677-5af1-86db-20a851ce67ea

STIX ID: report--ab2fbf07-8677-5af1-86db-20a851ce67ea

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Tushar Subhra Dutta

...
...

A credential‑stealing malware named Vidar has emerged as a prominent threat in early 2026, distributed via fake software downloads promoted through YouTube and file‑sharing sites; the campaign uses a staged installer (NeoHub.exe) loading a malicious msedge_elf.dll packed with GO-based protections, fake code-signing certificates, and a Dead Drop Resolver (Steam profiles/Telegram) to locate C2, targets multiple browsers and crypto wallets, and is linked to various threat actors including Scattered Spider with stolen credentials sold on Russian Market.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.