logo

Vidar Stealer Campaign Evades EDR to Steal Credentials

ID: c01be48c-ead9-5bc6-91b6-6e27fb431913

STIX ID: report--c01be48c-ead9-5bc6-91b6-6e27fb431913

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Mayura Kathir

...
...

This report documents a Vidar Stealer campaign that uses spear‑phishing ZIPs containing obfuscated LNK files to launch cmd.exe and PowerShell, download obfuscated BAT and compiled Python bytecode payloads, and establish a persistent, stealthy backdoor (renamed pythonw.exe + scheduled tasks) for credential theft and remote command execution; it includes TTP analysis, IOCs (hashes, domains, IPs), and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.