logo

C2 powered by Steam

ID: fcc88784-5b97-5936-ab55-f92f18392b3f

STIX ID: report--fcc88784-5b97-5936-ab55-f92f18392b3f

Feed Name: IntelInsights (Substack)

Threat Score
62/100

Date Published: 2024-11-10

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

The report documents an investigation into Vidar infostealer activity discovered via a MalwareBazaar hash and VirusTotal relations, linking infrastructure to Steam community usernames that include IP addresses in a consistent pattern. It highlights TTPs like DLL sideloading and fake distribution, shares IOCs including a SHA-256 sample and IPs (some active with redirection), and notes clustering within AS24940 while calling for further automated analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.