RST TI Report Digest: 28 Apr 2026
ID: cd879a30-ced1-5e9e-b5b4-29af592b68df
STIX ID: report--cd879a30-ced1-5e9e-b5b4-29af592b68df
Feed Name: RST Cloud Blog
This report details the rise of the Vidar infostealer—now reportedly the top infostealer in the Russian market since November 2025—highlighting the October 2025 Vidar 2.0 release, distribution via spearphishing, drive-by downloads and disguised software, components such as NeoHub.exe and msedge_elf.dll, use of dead-drop resolvers on Steam and Telegram for C2/exfiltration, and extensive IOCs (IPs, domains, URLs, file hashes and malicious browser extensions) to aid detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
