Vidar Stealer 2.0 Exploits GitHub, Reddit to Deliver Malware via Fake Game Cheats
ID: 82675a8e-b8d9-5409-80e7-52d279a66ef4
STIX ID: report--82675a8e-b8d9-5409-80e7-52d279a66ef4
Feed Name: Infosecurity Magazine (News)
Threat Score
**Executive summary:** Acronis TRU identified widespread campaigns distributing the Vidar 2.0 infostealer via hundreds of GitHub repositories and Reddit/Discord-promoted fake game cheats; multi-stage loaders (PowerShell compiled to .NET, AutoIt) add Defender exclusions, download Themida-packed Vidar, establish persistence (scheduled tasks), and exfiltrate credentials, tokens and wallets using Telegram and Steam-based dead-drop resolvers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
