Tracking Vidar Infrastructure with Censys
ID: fa16fbcc-f203-5c47-b8ed-afc9bd1e697f
STIX ID: report--fa16fbcc-f203-5c47-b8ed-afc9bd1e697f
Feed Name: Censys Blog
This report analyzes the Vidar infostealer: how it obtains C2 addresses (primarily via Telegram and fallback Steam accounts), the data-exfiltration workflow (DLL retrievals, screenshots, browser credentials) sent over HTTPS, and identifies C2 servers by unique TLS certificate subject/issuer DNs discoverable with Censys. It documents an observed footprint of ~22 C2 hosts concentrated in specific ASNs and links Vidar to the Scattered Spider threat actor, noting its use in data theft and extortion campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
