Vidar stealer campaign targeting Baltic region and NATO entities
ID: 77b9a415-9199-55b0-a1b4-c241f930b0f0
STIX ID: report--77b9a415-9199-55b0-a1b4-c241f930b0f0
Feed Name: CERT Polska
Threat Score
This report analyzes a Vidar Stealer sample (SHA256 b115531ef...) and describes its string decryption, hostname-based filtering of stolen credentials, and dual C2 behavior where alternate C2 endpoints are fetched from Mastodon profiles; it enumerates targeted government-related hostnames, Mastodon profile proxies, two C2 IPs, and a large set of sample hashes and feeds linking the campaign to other stealers and loaders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
