Inside the Stealthy Evolution of Vidar Infostealer
ID: d161476c-e882-57a3-9a50-b5df80d014bb
STIX ID: report--d161476c-e882-57a3-9a50-b5df80d014bb
Feed Name: securityonline.info
Threat Score
Vidar has transformed from a credential stealer into a multi-stage, stealth-driven infostealer that uses Go-compiled droppers, a living‑off‑the‑land execution chain (WScript → PowerShell → ConHost → RegAsm), fileless reflective .NET loading, and social-engineering lures (fake GitHub repos, CAPTCHAs, game cheats) to harvest crypto wallets and password managers and exfiltrate data via Telegram.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
