Hacked sites deliver Vidar infostealer to Windows users
ID: fedb2791-b64e-54bf-ba70-4034fa8d2493
STIX ID: report--fedb2791-b64e-54bf-ba70-4034fa8d2493
Feed Name: Malwarebytes Blog
## Executive summary This report describes an active campaign distributing the Vidar infostealer through fake CAPTCHA pages injected into compromised WordPress sites across multiple countries; the attack chain uses mshta to run an obfuscated HTA that downloads a malicious MSI which executes a Go loader that decrypts and loads Vidar into memory. The document includes technical analysis of the HTA/MSI/loader behavior, anti-analysis checks, injected site code, and IOCs (malicious domains, Telegram and Steam C2 references), and provides user-focused mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
