New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
ID: 51e05e28-83f0-5eab-a97b-ff5b97c1a168
STIX ID: report--51e05e28-83f0-5eab-a97b-ff5b97c1a168
Feed Name: Infosecurity Magazine (News)
Unit 42 reported an active global malvertising campaign (detected April 2026) that delivers a loader via password-protected .bin archives to evade detection; the loader drops Vidar infostealer to harvest browser credentials, cookies and crypto wallets, and XMRig to mine Monero. The attackers use anti-analysis techniques including an AMSI bypass and process enumeration, employ the Factory-v3 MaaS framework (99 samples observed), and use Telegram for C2, running a dual monetization model of selling stolen credentials/cookies and harvesting mining revenue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
