logo

Hacked sites deliver Vidar infostealer to Windows users

ID: fedb2791-b64e-54bf-ba70-4034fa8d2493

STIX ID: report--fedb2791-b64e-54bf-ba70-4034fa8d2493

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-03-16

Date Updated: 2026-04-28

...
...

## Executive summary This report describes an active campaign distributing the Vidar infostealer through fake CAPTCHA pages injected into compromised WordPress sites across multiple countries; the attack chain uses mshta to run an obfuscated HTA that downloads a malicious MSI which executes a Go loader that decrypts and loads Vidar into memory. The document includes technical analysis of the HTA/MSI/loader behavior, anti-analysis checks, injected site code, and IOCs (malicious domains, Telegram and Steam C2 references), and provides user-focused mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.