logo

Tracking Vidar Infrastructure with Censys

ID: fa16fbcc-f203-5c47-b8ed-afc9bd1e697f

STIX ID: report--fa16fbcc-f203-5c47-b8ed-afc9bd1e697f

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2023-11-22

Date Updated: 2026-04-27

Author: Brenda Mendoza

...
...

This report analyzes the Vidar infostealer: how it obtains C2 addresses (primarily via Telegram and fallback Steam accounts), the data-exfiltration workflow (DLL retrievals, screenshots, browser credentials) sent over HTTPS, and identifies C2 servers by unique TLS certificate subject/issuer DNs discoverable with Censys. It documents an observed footprint of ~22 C2 hosts concentrated in specific ASNs and links Vidar to the Scattered Spider threat actor, noting its use in data theft and extortion campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.