logo

Microsoft Windows 11 help Files have Vidar Spyware

ID: 33382028-9108-58e1-a58a-0613db89d301

STIX ID: report--33382028-9108-58e1-a58a-0613db89d301

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

ThreatLabz describes an active Vidar infostealer campaign where attackers distribute oversized ISO files (spoofing Windows 11) and backdoored Adobe Photoshop binaries to deliver Themida-packed Vidar samples; the malware retrieves C2 addresses from attacker-controlled Telegram and Mastodon profiles, and the report includes detailed technical analysis, file hashes, malicious domains, C2 IPs, and other IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.