logo

Vidar Stealer Weaponizes AutoIt and Masqueraded Scripts

ID: 862c1fee-f430-53d3-9965-0c5722a3722a

STIX ID: report--862c1fee-f430-53d3-9965-0c5722a3722a

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

LevelBlue analyzed a multi-stage Vidar Stealer campaign that begins with a trojanized MicrosoftToolkit.exe and a renamed Swingers.dot -> a.bat drop, uses an AutoIt-compiled loader (Replies.scr) and native utilities (e.g., extract32.exe) to reconstruct payloads, and establishes active C2 for exfiltration of browser credentials, cookies, cryptocurrency wallets and other sensitive data; the actors employ self-cleanup to hinder forensics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.