Hacked sites deliver Vidar infostealer to Windows users
ID: 2f1c9403-1b84-5ca1-b98c-c2ec0eb08556
STIX ID: report--2f1c9403-1b84-5ca1-b98c-c2ec0eb08556
Feed Name: Security Boulevard
Malicious actors have been delivering the Vidar infostealer through fake CAPTCHA pages injected into compromised WordPress sites across multiple countries; victims are instructed to run a mshta command which launches an obfuscated HTA that downloads an MSI installer. The MSI executes a GoLang loader that performs anti-analysis checks, decrypts Vidar, and loads it into memory to harvest browser credentials, cryptocurrency data, cookies, and other sensitive information; the report includes injected code behavior, infection chain details, and several domains and C2 endpoints as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
