Vidar Stealer is a Windows infostealer descended from the Arkei codebase and operated through a malware-as-a-service ecosystem with financially motivated affiliates. It is widely used to steal browser credentials, cookies, browsing history, autofill data, cryptocurrency wallet data, system information, files, and data from applications such as Telegram and Discord. Recent variants and campaigns also target browser extensions, including cryptocurrency wallets, password managers, and authenticator extensions, and some observed activity includes keylogging and retrieval of additional payloads.
Vidar is commonly delivered through social-engineering-heavy distribution chains rather than direct exploitation. Observed delivery vectors include malvertising, fake cracked-software downloads, deceptive GitHub repositories, fake CAPTCHA or ClickFix lures that trick users into executing commands, and compromised websites used to redirect victims into staged malware flows. It is also seen as a downstream payload of shared loaders and multi-stage delivery frameworks, including DLL sideloading chains and Go-based loaders designed to evade detection through code-signing abuse, oversized padded binaries, obfuscation, and in-memory execution.
On infected systems, Vidar typically focuses on credential and session theft from browsers and related applications, often harvesting cookies that can support account takeover. It has also been observed collecting cryptocurrency wallet artifacts and other locally stored sensitive data, packaging stolen information for exfiltration to attacker-controlled infrastructure. Some campaigns establish persistence through scheduled tasks, startup mechanisms, or registry autoruns, while others use Vidar as an intermediate monetization stage alongside additional malware such as XMRig cryptominers, RATs, or proxy-capable post-exploitation tooling.
Vidar is frequently associated with broad, opportunistic victimization of consumers, developers, and small and medium-sized businesses, though it also appears in intrusions affecting enterprise environments and sector-specific operations. Its mature affiliate ecosystem, flexible loader compatibility, and continued evolution into stealthier multi-stage chains have made it one of the most prevalent commodity stealers in active criminal operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5142 (ClearFake Cluster): Primarily uses the BNB Smart Chain to distribute infostealers such as LUMMAC.V2 and Vidar via compromised WordPress sites.
Once activated, this malware frequently drops the notorious Vidar stealer to scrape sensitive data from the host machine.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
Users who downloaded the archives received a loader that silently installed Vidar infostealer on their devices.
Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors are targeting consumers and small to midsize businesses (SMBs) globally in a financially motivated malvertising campaign... An attack begins when someone clicks on a malicious online ad for pirated or cracked software, which redirects them to attacker-controlled websites hosting the password-protected archives
Operators distribute malware through pirated software repositories, malvertising networks, and compromised websites with the goal of infecting as many machines as possible.
Finally, the loader establishes persistence through Windows Registry Run keys and scheduled tasks to ensure the malware survives system reboots.
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com.
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result with execution-policy bypass.
This dropper extracts and deploys a VBScript file , which contains embedded PowerShell code responsible for continuing the infection chain.
Finally, the loader establishes persistence through Windows Registry Run keys and scheduled tasks to ensure the malware survives system reboots.
This method further retrieves an additional payload from a reversed and obfuscated URL, decodes it, and executes it potentially via process injection while also supporting optional persistence mechanisms
Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
This indicates that the loader dynamically resolves Win32 APIs at runtime rather than relying on a static import table.
A Go module that posed as a DNS and subdomain scanner while acting as a first-stage Windows malware loader.
This method further retrieves an additional payload from a reversed and obfuscated URL, decodes it, and executes it potentially via process injection while also supporting optional persistence mechanisms
Process injection techniques such as RunPE / process hollowing using APIs like CreateProcess, WriteProcessMemory, and CreateRemoteThread.
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result... Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
Step 2: Anti-Analysis Check If sandbox detected → WScript.Quit Else -> Continue execution
The loader extracts it into a directory named to resemble a legitimate Microsoft Photos install and launches Microsoft.exe from that path with a hidden window.
If enabled, the sample invokes a hidden PowerShell instance (-WindowStyle Hidden)
They extract: Browser-saved credentials, autofill data Active session cookies (which bypass MFA entirely) Authentication tokens for GitHub, GitLab, AWS, Azure, and GCP
During the initial stage of network communication, we observed the sample establishing a connection to the attacker-controlled IP 62.60.226.200 , requesting the resource /public_files/160066.jpg?12711313.
Rather than hardcoding a payload URL, the resolver retrieves text from public platforms, searches it for the marker string 'LastW,' then decrypts the trailing blob with a hardcoded key to recover the actual download location. Primary dead drops include Pastebin and a paste service called Rlim, with fallbacks across YouTube, Instagram, Telegram, Google Docs, and GitCode.
553 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer mentioned as an example of live C2 infrastructure tracked by Hudson Rock Threat Feeds.
Mentioned only as an example of another tag that should reduce confidence when attributing activity to Kratos.
Vidar10
A stealer mentioned as an additional payload associated with prior public reporting on BoryptGrab campaigns, not as the primary payload in this campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.