Vidar Malware Campaign Targets Login Credentials, Session Cookies, and Wallet Files
ID: ea653833-b723-5406-aacd-9cf5d7ed17c1
STIX ID: report--ea653833-b723-5406-aacd-9cf5d7ed17c1
Feed Name: Cyber Press
A malicious campaign uses a trojanized Microsoft Toolkit installer to deploy the Vidar info stealer. The chain stages a disguised container (renamed .bat) that extracts an AutoIt-compiled loader (Replies.scr) and an encrypted payload (D) which, after anti-analysis checks, exfiltrates browser credentials and crypto wallet data via C2 mechanisms (Telegram, Steam profile polling, gz.technicalprorj.xyz). The report includes MITRE ATT&CK mappings and actionable IOCs (SHA-256 hashes, IP and domains) and notes defensive evasion and post-execution cleanup to hinder detection and forensics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
