logo

Hacked sites deliver Vidar infostealer to Windows users

ID: 2f1c9403-1b84-5ca1-b98c-c2ec0eb08556

STIX ID: report--2f1c9403-1b84-5ca1-b98c-c2ec0eb08556

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

Author: Malwarebytes

...
...

Malicious actors have been delivering the Vidar infostealer through fake CAPTCHA pages injected into compromised WordPress sites across multiple countries; victims are instructed to run a mshta command which launches an obfuscated HTA that downloads an MSI installer. The MSI executes a GoLang loader that performs anti-analysis checks, decrypts Vidar, and loads it into memory to harvest browser credentials, cryptocurrency data, cookies, and other sensitive information; the report includes injected code behavior, infection chain details, and several domains and C2 endpoints as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.