logo

Vidar Stealer 2.0 Exploits GitHub, Reddit to Deliver Malware via Fake Game Cheats

ID: 82675a8e-b8d9-5409-80e7-52d279a66ef4

STIX ID: report--82675a8e-b8d9-5409-80e7-52d279a66ef4

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

...
...

**Executive summary:** Acronis TRU identified widespread campaigns distributing the Vidar 2.0 infostealer via hundreds of GitHub repositories and Reddit/Discord-promoted fake game cheats; multi-stage loaders (PowerShell compiled to .NET, AutoIt) add Defender exclusions, download Themida-packed Vidar, establish persistence (scheduled tasks), and exfiltrate credentials, tokens and wallets using Telegram and Steam-based dead-drop resolvers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.