Malicious PirateFi game infects Steam users with Vidar malware
ID: c329fefc-0f20-57a5-a531-4a0335be4c92
STIX ID: report--c329fefc-0f20-57a5-a531-4a0335be4c92
Feed Name: Bleeping Computer
A malicious free-to-play Steam game called PirateFi (available Feb 6–12) distributed the Vidar infostealer hidden in Pirate.exe (payload Howard.exe) packed with InnoSetup; Steam notified potentially affected users and up to ~1,500 downloads may have exposed credentials, cookies, email clients and cryptocurrency wallets. SECUINFRA confirmed the sample as Vidar via dynamic analysis and YARA; the actor used obfuscation and rotating C2 servers. Recommended mitigations include full antivirus scans, changing passwords, enabling MFA, and considering a full OS reinstall.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
