Skip to main content
Mallory
MalwareRansomwareUsed by 10 actors

Vidar

Also known asVidar Stealer

Vidar is a Windows information-stealing malware family, widely referred to as Vidar Stealer, and described in the content as an Arkei-derived or Arkei fork/copycat stealer first seen in 2018. Its core capability is theft and exfiltration of sensitive data from compromised hosts, including credentials, browser-stored data, cookies, authentication/session tokens, credit card information, cryptocurrency wallets, clipboard contents, screenshots, cached credentials, installed application data, and general system information. Multiple sources in the content specifically note that Vidar can retrieve browser cookies, including from recent Chrome versions, and that it is used in mass credential-harvesting campaigns.

Observed behavior includes downloading legitimate DLL dependencies from its C2 infrastructure, using HTTP GET to retrieve files such as freebl3.dll, mozglue.dll, msvcp140.dll, nss3.dll, softokn3.dll, and vcruntime140.dll, and exfiltrating stolen data in ZIP archives over HTTP POST. Additional reported behaviors include monitoring clipboard content, taking screenshots, reading cached credentials of various applications, possible persistence via registry run keys or startup folders, and use of HTTP/S web protocols for command-and-control and exfiltration. ASD reporting states that some Vidar campaigns obtain initial C2 details through dead-drop resolvers such as Telegram bots and Steam profiles, then beacon and exfiltrate via HTTP/S POST. The malware also uses defense-evasion techniques including obfuscation, self-deletion of the initial executable, and primarily in-memory execution in at least some delivery chains.

The content links Vidar to several infection and delivery vectors. Reported distribution methods include malvertising campaigns, phishing emails, drive-by downloads, ClickFix social-engineering lures, compromised WordPress sites, malicious Word documents using remote template injection via the Colibri loader, CHM-based phishing, fake browser or verification prompts, binders/loaders, Discord CDN abuse, and ClearFake campaigns. In the Australian ClickFix activity, compromised WordPress pages displayed a fake Cloudflare verification prompt, copied an obfuscated PowerShell command to the clipboard, and instructed the user to execute it with administrative privileges, after which Vidar was downloaded and launched.

Vidar is repeatedly associated with financially motivated cybercrime and credential-access ecosystems. The content ties it to mass infostealer campaigns affecting Snowflake-related compromises, FIFA-themed credential theft, and broader credential pipelines alongside Lumma, RedLine, RisePro, Raccoon Stealer, and MetaStealer. It is also mentioned in operations or infrastructure linked to Fox Tempest malware-signing abuse, Vanilla Tempest, Scattered Spider phishing activity, and ransomware-adjacent ecosystems involving families such as Rhysida, Akira, INC, Qilin, and BlackByte. High-confidence infrastructure and sample indicators directly mentioned in the content include SHA-256 b4c9aadd18c1b6f613bf9d6db71dcc010bbdfe8b770b4084eeb7d5c77d95f180 for a September 2019 Vidar sample; C2 infrastructure 104.200.67[.]209:80 and dersed[.]com for that sample; and a VMRay-analyzed sample bPqn6zc9i6TeEqXz.exe with MD5 1ce37c9a9b307500590e7851f2b9a282, SHA1 d06b99394887747fa28f91fb19de214187467448, and SHA256 62338c7764f4e82105ea52fab868e1f04dc2f54bb44c5a47ddac685eacd6ed3c.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Vanilla Tempest

Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.

via security affairssecurityaffairs.com
Fox Tempest

Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.

via security affairssecurityaffairs.com
Scattered Spider

Apart from the above legitimate tools used for malicious purposes, Scattered Spider also conducts phishing attacks to install malware like the WarZone RAT, Raccoon Stealer, and Vidar Stealer, to steal from compromised systems login credentials, cookies, and other data useful in the attack.

via bleeping computerbleepingcomputer.com
Storm-0501

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

via cyber security newscybersecuritynews.com
Storm 2561

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

via cyber security newscybersecuritynews.com
Storm-0249

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

via cyber security newscybersecuritynews.com
EncryptHub

“...HijackLoader malware ... downloads the Vidar infostealer (v9d9d.exe).”

via bleeping computerbleepingcomputer.com
WIZARD SPIDER

...new malware strains such as ... Vidar.

via the hacker newsthehackernews.com
Zestix

...relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.

via dark readingdarkreading.com
UNC5142

"...information stealers... Vidar..."

via cloudatg insightscloudatg.com
MITRE ATT&CK

Techniques & procedures

34 distinct techniques documented for this family, organized by ATT&CK tactic.

Reconnaissance

1 technique
T1593Search Open Websites/DomainsEvidence1

The actors behind Vidar spread it by adding comments on YouTube that contain links to a ZIP or RAR archive hosted on a file-sharing platform which is changing every week.

T1583Acquire InfrastructureEvidence3

Vidar and Lumma malware are delivered through cracked software lures, malvertising networks, and Telegram cheat channels.

T1583.001DomainsEvidence1

Acquire Infrastructure: Domains T1583.001 Adversary obtains domains to use for ClickFix attacks, payload delivery and C2 Infrastructure.

T1584.006Web ServicesEvidence1

Compromise Infrastructure: Web Services T1584.006 Adversary leverages legitimate domain infrastructure to use as attack vector.

T1587.001MalwareEvidence1

Further analysis revealed that Fox Tempest expanded its offerings earlier this year by providing customers with pre-configured virtual machines hosted through Cloudzy infrastructure. Users could upload malware to these systems and receive digitally signed binaries generated through certificates controlled by the group.

T1588.001MalwareEvidence1

Obtain Capabilities: Malware T1588.001 Adversary obtains Vidar Stealer to steal sensitive information.

T1588.005ExploitsEvidence1

Obtain Capabilities: Exploits T1588.005 Adversary obtains exploits to compromise legitimate WordPress webpages.

T1608.006SEO PoisoningEvidence2

Доставка. Фишинг, поддельный установщик, SEO-poisoning. Пользователь запускает малварь на своём устройстве.

Initial Access

3 techniques
T1078Valid AccountsEvidence2

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

T1189Drive-by CompromiseEvidence2

Malvertising campaigns, phishing emails, and drive-by downloads have been mostly leveraged to spread Vidar

T1566PhishingEvidence2

Доставка. Фишинг, поддельный установщик, SEO-poisoning. Пользователь запускает малварь на своём устройстве.

Execution

4 techniques
T1059.001PowerShellEvidence1
TacticExecution

Command and Scripting Interpreter: PowerShell T1059.001 Adversary utilises PowerShell commands to download and deploy a malware executable from the internet.

T1204User ExecutionEvidence1
TacticExecution

As can be seen, the user is tricked into thinking that they have launched the Homebrew app and opening the AMOS stealer.

T1204.004Malicious Copy and PasteEvidence1
TacticExecution

User Execution: Malicious Copy and Paste T1204.004 Adversary relies upon a user pasting the PowerShell command – which has been copied to their clipboard by a malicious script – into the command line as administrator.

T1574.001DLLEvidence1

vcomp100.dll: malicious DLL used for DLL hijacking; ... The legitimate converter.exe loads vcomp100.dll as the former is vulnerable to DLL hijacking.

Persistence

1 technique
T1078Valid AccountsEvidence2

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

T1055Process InjectionEvidence1

Vidar has been able to evade detection with its use of ... process injection

T1078Valid AccountsEvidence2

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

Stealth

7 techniques
T1027Obfuscated Files or InformationEvidence1
TacticStealth

Obfuscated Files or Information T1027 PowerShell command which is copied to the user’s clipboard is heavily obfuscated. This makes detection of the malware delivery URL or analysis of the command difficult.

T1036MasqueradingEvidence3
TacticStealth

the service enabled cybercriminals to disguise malware as trusted software, improving the likelihood that malicious files would bypass security controls and be executed by victims.

T1055Process InjectionEvidence1

Vidar has been able to evade detection with its use of ... process injection

T1070.004File DeletionEvidence1
TacticStealth

Indicator Removal: File Deletion T1070.004 Upon execution the file will delete itself and exist in memory to evade detection and prevent analysis of the executable file.

T1078Valid AccountsEvidence2

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

T1140Deobfuscate/Decode Files or InformationEvidence1
TacticStealth

Next, the malicious DLL reads the encrypted “bake.docx” file, gets the payload and the key from a specified offset, and decodes the payload.

T1574.001DLLEvidence1

vcomp100.dll: malicious DLL used for DLL hijacking; ... The legitimate converter.exe loads vcomp100.dll as the former is vulnerable to DLL hijacking.

T1553.002Code SigningEvidence4

Microsoft has announced the disruption of a large-scale malware-signing-as-a-service (MSaaS) operation that exploited its Azure Artifact Signing platform to generate fraudulent code-signing certificates... The group allegedly abused Microsoft's Artifact Signing service to create short-lived digital certificates that allowed malware to appear legitimate to both users and operating systems.

Credential Access

6 techniques
T1056Input CaptureEvidence1

Vidar has been able to evade detection with its use of ... API hooking

T1528Steal Application Access TokenEvidence1

the stealers copy all browser-stored credentials, cookies, autofill data, session tokens, and cryptocurrency wallet seeds from every infected device.

T1539Steal Web Session CookieEvidence3

These stealers copy every browser-stored credential, session token, and cryptocurrency wallet seed from infected devices.

T1555Credentials from Password StoresEvidence2

the stealers copy all browser-stored credentials, cookies, autofill data, session tokens, and cryptocurrency wallet seeds from every infected device.

T1555.003Credentials from Web BrowsersEvidence1

Инфостилер читает файлы и память браузера, где лежат сессионные куки - Credentials from Web Browsers (T1555.003, Credential Access).

T1649Steal or Forge Authentication CertificatesEvidence1

Information stealers, which are used to collect credentials to then sell them on the dark web or use in subsequent cyberattacks, are actively distributed by cybercriminals.

Collection

2 techniques
T1005Data from Local SystemEvidence1

Vidar ... could facilitate the covert exfiltration of targeted systems' data, including credentials, credit card information, and authentication tokens

T1056Input CaptureEvidence1

Vidar has been able to evade detection with its use of ... API hooking

T1071.001Web ProtocolsEvidence1

Application Layer Protocol: Web Protocols T1071.001 Adversary uses POST requests to carry stolen information to the C2 server while blending in with normal HTTP/S traffic.

T1102.001Dead Drop ResolverEvidence2

Vidar has been able to evade detection with its use of a Telegram and Steam profile-exploiting dead drop resolver technique

T1105Ingress Tool TransferEvidence2

Researchers found that the malware-signing operation enabled customers to upload malicious files and receive code-signed versions using fraudulently acquired certificates.

T1573Encrypted ChannelEvidence1

Vidar has been able to evade detection with its use of ... Transport Layer Security Encryption

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Vidar ... could facilitate the covert exfiltration of targeted systems' data

Other

1 technique
T1562Impair DefensesEvidence1

Vidar has been able to evade detection with its use of ... Antimalware Scan Interface bypasses

INDICATORS OF COMPROMISE

IOCs tracked for this family

253 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
124 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
53 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
76 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in apptoday
uri●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in app3 days ago
uri●●●●●●●●●●●●View more in app3 days ago
uri●●●●●●●●●●●●View more in app3 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching253

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution10

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping34

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.