logo

Vidar stealer campaign targeting Baltic region and NATO entities

ID: 77b9a415-9199-55b0-a1b4-c241f930b0f0

STIX ID: report--77b9a415-9199-55b0-a1b4-c241f930b0f0

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2021-10-27

Date Updated: 2026-04-19

Author: CERT Polska

...
...

This report analyzes a Vidar Stealer sample (SHA256 b115531ef...) and describes its string decryption, hostname-based filtering of stolen credentials, and dual C2 behavior where alternate C2 endpoints are fetched from Mastodon profiles; it enumerates targeted government-related hostnames, Mastodon profile proxies, two C2 IPs, and a large set of sample hashes and feeds linking the campaign to other stealers and loaders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.