Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
ID: b47310ff-4dc3-54f1-b114-95404ede57ce
STIX ID: report--b47310ff-4dc3-54f1-b114-95404ede57ce
Feed Name: Palo Alto Networks Unit 42
Date Published: 2026-07-07
Date Updated: 2026-07-23
Author: Bharath Nannaka and Pranay Kumar Chhaparwal
In April 2026 Unit 42 identified a global financially motivated campaign using malvertising to distribute Factory-v3 Go-based loaders that deploy Vidar stealer and an XMRig Monero miner; the campaign uses fake Authenticode certificates, file-size inflation, an AMSI in-memory bypass, DLL sideloading and multiple persistence mechanisms, and includes extensive IoCs (IP addresses, file hashes, file paths and registry/task persistence indicators) and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
