logo

Vidar Stealer 2.0 Spreads via Fake Game Cheats Shared on GitHub and Reddit

ID: 5ff3b8a1-c872-5464-872e-bd15748b5d81

STIX ID: report--5ff3b8a1-c872-5464-872e-bd15748b5d81

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Large-scale campaigns are abusing GitHub, Reddit and Discord to distribute Vidar Stealer 2.0 via fake “free game cheats” and sideloaded installers; operators hide payloads behind images and third-party redirects, use GitHub Pages and password-protected archives, and employ loaders (PowerShell-in-.NET, AutoIt, VBS) that deploy a Themida-packed Vidar 2.0 which harvests browser credentials, cookies, crypto wallets, Azure tokens, Steam/Discord/Telegram artifacts and exfiltrates via Telegram/Steam dead drops — the report highlights extensive evasion (morphing, obfuscation, sandbox checks), widespread targeting of gamers (including minors), and recommends treating gaming-related downloads and unapproved executables as high-risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.