logo

Fake YouTube Downloads Spread Vidar Malware to Steal Corporate Logins

ID: 565af039-78a0-5387-8dc6-14fde8ac4a6b

STIX ID: report--565af039-78a0-5387-8dc6-14fde8ac4a6b

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Mayura Kathir

...
...

A Vidar 2.0 infostealer campaign is distributing a malicious NeoHub installer via fake YouTube download links and file‑sharing services; the packed Go DLL (msedgeelf.dll) harvests browser credentials, cookies, autofill data and crypto wallets, uses Steam/Telegram dead‑drop resolvers to retrieve C2, and the resulting logs are traded on Russian Market and Telegram channels—posing high risk of credential theft, session replay (MFA bypass in some cases), and downstream account takeovers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.