Fake YouTube Downloads Spread Vidar Malware to Steal Corporate Logins
ID: 565af039-78a0-5387-8dc6-14fde8ac4a6b
STIX ID: report--565af039-78a0-5387-8dc6-14fde8ac4a6b
Feed Name: GBHackers
Threat Score
A Vidar 2.0 infostealer campaign is distributing a malicious NeoHub installer via fake YouTube download links and file‑sharing services; the packed Go DLL (msedgeelf.dll) harvests browser credentials, cookies, autofill data and crypto wallets, uses Steam/Telegram dead‑drop resolvers to retrieve C2, and the resulting logs are traded on Russian Market and Telegram channels—posing high risk of credential theft, session replay (MFA bypass in some cases), and downstream account takeovers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
