logo

New Vidar 2.0 Infostealer Spreads via Fake Game Cheats on GitHub, Reddit

ID: 9cdba286-538b-5b53-8c64-c06abca74670

STIX ID: report--9cdba286-538b-5b53-8c64-c06abca74670

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Acronis TRU researchers uncovered a large campaign that distributes Vidar 2.0—an actively sold infostealer—through social platforms and GitHub pages disguised as free game cheats. Vidar 2.0 has been rewritten for greater speed and stealth, uses PowerShell droppers and persistence, detects and avoids analysis environments, exfiltrates cryptocurrency wallets, Discord/Steam/Telegram tokens, cloud and server credentials (e.g., Azure, FileZilla), takes screenshots, and uses Telegram bots and Steam profiles as covert command/dead-drop channels; hundreds of malicious pages were found and the true scale may be much larger.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.