logo

Vidar Rises to Top of Chaotic Infostealer Market

ID: ef128251-7cdc-5bf3-b8e2-8e36978c4a24

STIX ID: report--ef128251-7cdc-5bf3-b8e2-8e36978c4a24

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Jai Vijayan

...
...

Intrinsec reports that Vidar, an infostealer active since 2018, has surged to the top of the infostealer ecosystem after upgrades and expanded distribution following law-enforcement takedowns of competitors; attackers are using phishing, trojanized packages, fake game cheats and Telegram "cloud" channels to spread it. Vidar harvests saved passwords, cookies, session tokens, browser-stored crypto wallets, email client data, screenshots and local files, uses dead-drop resolvers to hide C2, and its stolen credentials are monetized on underground markets; recommended defenses include MFA for browser accounts, DNS filtering/secure web gateways, and sandboxing of attachments and URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.