logo

Vidar Infostealer Hammers SMBs via Malvertising Campaign

ID: 306f5a83-27b7-545b-b4ad-d746dc121263

STIX ID: report--306f5a83-27b7-545b-b4ad-d746dc121263

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-07-08

Date Updated: 2026-07-17

Author: Elizabeth Montalbano

...
...

Unit 42 uncovered a malvertising campaign that lures users to attacker-controlled sites offering cracked software; downloaded password-protected archives execute a Go-based Factory-v3 loader that employs AMSI bypasses, fake code-signing, and large-file padding to evade detection, then drops the Vidar infostealer (harvesting browser credentials, cookies, crypto wallets, etc.) and the XMRig Monero miner, establishes persistence via Run keys and scheduled tasks, and includes IoCs for defenders to block C2 and mining pools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.