logo

Fake Gemini installer delivers Vidar infostealer via Google Colab lure

ID: ee48390b-14e7-584c-af79-f481a3b209ad

STIX ID: report--ee48390b-14e7-584c-af79-f481a3b209ad

Feed Name: Help Net Security

Threat Score
65/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Sinisa Markovic

...
...

Darktrace investigated a campaign that used a fake “Google Gemini” installer hosted via Google Colab and a redirect to a malicious site to deliver a Go-compiled Vidar infostealer. The ZIP included instructions to run the executable as admin and exclude it from antivirus; the malware contacted Telegram-based C2 at dtm.kijangturbo88.top and focused on stealing browser credentials. Darktrace’s systems detected anomalous behavior, blocked C2 communications, and quarantined the infected host, highlighting the misuse of trusted platforms and AI-themed lures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.