logo

Inside the Stealthy Evolution of Vidar Infostealer

ID: d161476c-e882-57a3-9a50-b5df80d014bb

STIX ID: report--d161476c-e882-57a3-9a50-b5df80d014bb

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

Vidar has transformed from a credential stealer into a multi-stage, stealth-driven infostealer that uses Go-compiled droppers, a living‑off‑the‑land execution chain (WScript → PowerShell → ConHost → RegAsm), fileless reflective .NET loading, and social-engineering lures (fake GitHub repos, CAPTCHAs, game cheats) to harvest crypto wallets and password managers and exfiltrate data via Telegram.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.