Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityidentity-impersonation-fraudphishing-campaign-intelligenceai-enabled-threat-activity

Vidar Infostealer Spread Through Fake TikTok and Instagram Software Tutorials

Updated 9d agoFirst seen Jun 10, 20265 sources

Attackers are using TikTok and Instagram Reels to distribute Vidar infostealer through polished short videos that impersonate trusted brands and promise free access to premium software such as Spotify Premium and Microsoft Word. Reporting citing ReversingLabs says the clips use tutorial-style content, AI-generated voiceovers, and engagement bait to persuade users either to visit malicious download pages or to paste terminal and PowerShell commands that silently retrieve and run the malware.

The campaign replaces traditional phishing emails with social media-driven social engineering and benefits from recommendation algorithms and weak moderation, with one tracked video reportedly surpassing 109,000 views. Vidar, a malware-as-a-service infostealer, can steal passwords, banking data, browser cookies, credentials, and session tokens, while researchers said attacker accounts were able to evade reporting, delete warning comments, and block users who raised concerns. Defenders were urged to treat social platforms as an active malware delivery channel, restrict software installation rights, and train users not to execute untrusted commands from online videos.

Share:
Vidar Infostealer Spread Through Fake TikTok and Instagram Software Tutorials
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Jun 11, 202614d ago

ReversingLabs publishes IOCs for Vidar social-media campaigns

ReversingLabs published indicators of compromise to help defenders detect activity tied to the Vidar infostealer campaigns spread through TikTok and Instagram Reels. The IOCs accompanied its reporting on the fake software tutorial and promotional-video lures used in the operation.

Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware - Help Net Security
Jun 10, 202614d ago

ReversingLabs documents social-media Vidar delivery campaign

ReversingLabs documented malware campaigns on TikTok and Instagram Reels that used fake free-software tutorial videos and promotional clips to trick users into downloading or executing Vidar infostealer payloads. The lures impersonated trusted brands and directed victims either to malicious download pages or to run terminal or PowerShell commands that fetched the malware.

Scammers use short videos on social media to spread Vidar infostealer | brief | SC Media
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Malware
2 linked
Affected products
7 linked
TiktokWindowsPowershellTor BrowserWindows DefenderMicrosoft OfficeLinkedin
Organizations
10 linked
SpotifyReversingLabsMicrosoft CorporationLinkedinXGoogleTikTokMeta PlatformsMalwarebytesHackRead
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Vidar Infostealer Spread Through Fake TikTok and Instagram Software Tutorials | Mallory