logo

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

ID: b47310ff-4dc3-54f1-b114-95404ede57ce

STIX ID: report--b47310ff-4dc3-54f1-b114-95404ede57ce

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2026-07-07

Date Updated: 2026-07-23

Author: Bharath Nannaka and Pranay Kumar Chhaparwal

...
...

In April 2026 Unit 42 identified a global financially motivated campaign using malvertising to distribute Factory-v3 Go-based loaders that deploy Vidar stealer and an XMRig Monero miner; the campaign uses fake Authenticode certificates, file-size inflation, an AMSI in-memory bypass, DLL sideloading and multiple persistence mechanisms, and includes extensive IoCs (IP addresses, file hashes, file paths and registry/task persistence indicators) and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.