Vidar Infostealer Spreads via Fake CAPTCHAs, Hides in JPEG and TXT Files
ID: 628368b1-9ef7-5be4-b2e0-cca89cd7dc4e
STIX ID: report--628368b1-9ef7-5be4-b2e0-cca89cd7dc4e
Feed Name: HackRead
Point Wild’s Lat61 team reports a 2026 Vidar infostealer campaign that evolved into a multi-stage, fileless framework: attackers seed fake GitHub repos and use social-engineering (fake CAPTCHAs, Discord/Reddit lures) to trick victims into running scripts that fetch seemingly benign JPEG/TXT files containing Base64-encoded payloads. The malware reconstructs and executes the final payload in memory via .NET reflective loading, abuses trusted Windows binaries (WScript, PowerShell, RegAsm.exe) for stealth and persistence, and exfiltrates stolen credentials, session data and crypto wallet information to attacker-controlled infrastructure (including IP 62.60.226.200, Telegram and Cloudflare-fronted domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
