logo

Vidar Malware is Back: New Aryaka Threat Research Report

ID: 3b23e2ba-4a23-5bd3-946a-d654cc8caa33

STIX ID: report--3b23e2ba-4a23-5bd3-946a-d654cc8caa33

Feed Name: Aryaka

Threat Score
70/100

Date Published: 2025-09-04

Date Updated: 2026-04-27

Author: Nicholas Morpus

...
...

Vidar, an info-stealing malware-as-a-service, has re-emerged in a campaign targeting everyday Windows users to steal browser-saved credentials, cookies, tokens, and wallet files; it uses phishing/shady downloads for initial access, persists across reboots, retrieves C2 from public dead-drops, and exfiltrates data over encrypted HTTPS. Aryaka highlights the risk of account takeover and downstream fraud or data exposure and recommends layered, identity-aware defenses (zero-trust access, SWG/NGFW/IPS, CASB/DLP) and unified visibility to detect and block these actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.