logo

New Vidar Stealer Campaign Targets User Credentials

ID: e5ded1cc-1f49-57ab-ba91-7a09549b66cf

STIX ID: report--e5ded1cc-1f49-57ab-ba91-7a09549b66cf

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Varshini

...
...

Researchers at the Genians Security Center uncovered a sophisticated APT37-linked campaign that uses tailored spear-phishing ZIP attachments containing malicious LNK shortcuts to execute obfuscated multi-stage payloads. The chain downloads a BAT which retrieves a legitimate Python embed, renames pythonw.exe to run a stealthy Python-based RAT (Vidar-like) that communicates with C2 servers, enabling credential theft, file exfiltration, and secondary payload deployment; the report includes C2 domains, an IP, and a payload filename as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.