logo

Vidar Stealer 2.0 adds multi-threaded data theft, better evasion

ID: 51c5a3f3-b7f4-52df-bca4-0f1e91de76a5

STIX ID: report--51c5a3f3-b7f4-52df-bca4-0f1e91de76a5

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-21

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Vidar Stealer 2.0 — Trend Micro reports that Vidar has been rewritten in C, adds multi-threaded data-stealing workers, extensive anti-analysis checks, and memory-injection techniques that can bypass Chrome AppBound encryption by extracting keys from browser memory; it targets browser data, cryptocurrency wallets, cloud credentials, Steam, Telegram and Discord, and exfiltrates via Telegram bots and URLs on Steam profiles, with activity rising since the release and expected growth through Q4 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.