logo

Vidar Malware: How the Multithreaded Windows Stealer Works

ID: b0e1d111-74f7-5597-9f21-24dc806ce3f4

STIX ID: report--b0e1d111-74f7-5597-9f21-24dc806ce3f4

Feed Name: Picus Security Articles

Threat Score
78/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: [email protected] (Umut Bayram)

...
...

Vidar is a commercially sold Windows infostealer (MaaS) rewritten in C with a multithreaded engine and advanced evasion (AMSI bypass, control-flow flattening, signed loader abuse, file-size inflation); it steals browser credentials (including bypassing Chrome App‑Bound Encryption via memory-forking and APC injection), wallets, tokens and files, and exfiltrates data via HTTP multipart POSTs to round‑robin C2 resolved through Telegram and Steam dead-drops, with distribution observed via malvertising and crackware loaders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.