Vidar

Malware updated 11 days ago (2024-10-23T00:01:08.789Z)
Download STIX
Preview STIX
Vidar is a Windows-based malware, written in C++, that primarily functions as an infostealer. It is based on the Arkei stealer and typically targets various types of data, using the ACR Stealer as an exfiltration module. However, in a unique twist, Vidar downloads the ACR stealer instead of stealing data directly. The final payload, which is the Vidar stealer, can be extracted using the IDAT loader extractor. Vidar's distribution has evolved over time, moving from traditional spam campaigns and cracked software to malicious Google Search ads and comments on YouTube containing links to a ZIP or RAR archive hosted on a file-sharing platform. The actors behind Vidar use a variety of methods to spread the malware, including adding comments on YouTube with links to archives hosted on frequently changing file-sharing platforms. These archives contain harmful files such as Rilide Stealer, Vidar Stealer, IceRAT (written in JPHP), and Nova Stealer, which users could unknowingly download and deploy onto their devices by interacting with the malware-serving ads. The Vidar Stealer is sold through a malware-as-a-service model, advertised and disseminated via dark web forums and Telegram groups. The Vidar infostealer admin panel provides a splash screen impersonating Midjourney, according to the ESET Threat Report H1 2024. The report also provided information about the C2 server extracted from two Vidar malware samples. Despite its proliferation, the purpose of some associated files, such as install.cmd XLSX files, remains unclear. These files appear to contain Facebook account names and specific monetary information. Vidar continues to pose a significant threat due to its stealthy delivery methods and damaging capabilities.
Description last updated: 2024-10-22T17:41:03.594Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Arkei Stealer is a possible alias for Vidar. The Arkei Stealer is a type of malware, specifically designed to infiltrate and exploit computer systems. This malicious software, written in C++, first emerged in May 2018 and has since been forked or rebranded several times. The malware can infect a system through various means such as suspicious
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Infostealer
Ransomware
Youtube
Exploit
Payload
Maas
Phishing
Cobalt Strike
Loader
Malware Loader
Telegram
Cybercrime
Scams
Credentials
Dropper
Android
Github
1password
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Redline Malware is associated with Vidar. Redline is a notorious malware, known for its infostealing capabilities and widespread usage among cybercriminals. It is designed to steal personal data from victims' devices, including usernames, passwords, saved form data like addresses, email addresses, phone numbers, and cryptocurrency wallets. Unspecified
12
The Raccoon Malware is associated with Vidar. Raccoon is a malicious software (malware) developed by Russian-speaking coders, first spotted in April 2019. It was designed to steal sensitive data such as credit card information, email credentials, cryptocurrency wallets, and more from its victims. The malware is offered as a service (MaaS) for $Unspecified
7
The Mars Malware is associated with Vidar. Mars is a malicious software (malware) that has been discovered by the Trend Micro Mobile Application Reputation Service (MARS) team. This malware, related to other known threats like Vidar and Redline, has been involved in cryptocurrency-mining and financially-motivated scam campaigns targeting Andis related to
3
The Batloader Malware is associated with Vidar. Batloader is a malware downloader posing as installers or updates for legitimate applications such as Microsoft Teams, Zoom, and others. This malicious software can infiltrate systems through suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, it can steal personalUnspecified
3
The Redline Stealer Malware is associated with Vidar. RedLine Stealer is a malicious software (malware) that was first identified in a packet capture (pcap) infection from July 2023. This malware, sold as a service on Telegram and online hacker forums, targets browsers to collect various data saved by the user, such as credentials and payment card detaUnspecified
3
The Risepro Malware is associated with Vidar. RisePro is a type of malware, specifically an info-stealer, designed to infiltrate and damage computer systems. It operates by exploiting vulnerabilities in a device, often through suspicious downloads, emails, or websites, typically without the user's knowledge. Once inside, RisePro can disrupt opeUnspecified
3
The Lummac2 Malware is associated with Vidar. LummaC2, a malware strain first discovered in 2022, has been identified as an infostealer that exploits PowerShell commands to infiltrate systems and exfiltrate sensitive data. Distributed as Malware-as-a-Service (MaaS), it was initially identified in Russian-speaking forums and is written in C. TheUnspecified
3
The Privateloader Malware is associated with Vidar. PrivateLoader is a notable malware that has been active since at least December 19, 2022. It acts as the first step in many malware schemes, often initiating an infection chain that leads to other malicious software. The malware can infiltrate systems through suspicious downloads, emails, or websiteUnspecified
3
The Minodo Malware is associated with Vidar. Minodo is a type of malware, a harmful program designed to exploit and damage computer systems. It can infiltrate your system through suspicious downloads, emails, or websites, often without the user's knowledge. Once inside, it can steal personal information, disrupt operations, or even hold data hUnspecified
2
The Royal Ransomware Malware is associated with Vidar. The Royal Ransomware, a harmful malware program designed to exploit and damage computer systems, operated from September 2022 through June 2023. It employed multi-threaded encryption to disrupt operations and hold data hostage for ransom. The ransomware was primarily disseminated through suspicious Unspecified
2
The Lumma Stealer Malware is associated with Vidar. Lumma Stealer is a sophisticated malware designed to exfiltrate information from compromised systems, primarily targeting system details, web browsers, and browser extensions among other data. The malware's command and control (C&C) servers were active on multiple occasions in 2024, including April Unspecified
2
The Netsupport Malware is associated with Vidar. NetSupport is a legitimate remote access software that has been exploited as a malware tool by various threat actors. It's often used in combination with other malicious software like BlackBasta Ransomware, IcedID, and occasionally Lumma Stealer, the most common infostealer in the world today. The mUnspecified
2
The Systembc Malware is associated with Vidar. SystemBC is a type of malware that has been heavily utilized in various cyber attacks, including those involving the BlackBasta ransomware group in 2023. The Play ransomware actors have also been known to use SystemBC alongside other command and control (C2) applications such as Cobalt Strike and toUnspecified
2
The Stealc Malware is associated with Vidar. StealC is a form of malware that specifically targets browser extensions and password managers. Its emergence was first reported in early 2023 and it quickly grew in popularity on the dark web due to its ability to bypass traditional security measures. The malware's modus operandi involves stealing Unspecified
2
The Diceloader Malware is associated with Vidar. Diceloader is a type of malware, short for malicious software, that is designed to infiltrate and damage computer systems. It can infect systems through various means such as suspicious downloads, emails, or websites, often without the user's knowledge. Once inside a system, it can steal personal inUnspecified
2
The Raccoon Stealer Malware is associated with Vidar. Raccoon Stealer, a malware-as-a-service (MaaS) operation, emerged in 2019, designed by Russian-speaking developers to steal victims' sensitive data such as credit card information, email credentials, and cryptocurrency wallets. The malware was initially promoted exclusively on Russian-speaking hackiUnspecified
2
The Amos Malware is associated with Vidar. The AMOS malware, first identified in early 2023, is a malicious software specifically designed to target macOS users. It infiltrates systems via suspicious downloads, emails, or websites, often deceiving users into believing they have launched legitimate applications such as the Homebrew app. Once is related to
2
The Atomic Macos Stealer Amos Malware is associated with Vidar. In April 2023, Cyble Research and Intelligence Labs (CRIL) discovered a new malware named Atomic macOS Stealer (AMOS) being advertised for sale on a Telegram channel. The malware was found to be part of a larger operation involving several other variants such as Vidar, Lumma, and Octo. These threat Unspecified
2
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Gandcrab Threat Actor is associated with Vidar. GandCrab, a threat actor, is known for its malicious activities involving ransomware attacks. Originating from Russian origins and evolving from Team Truniger, a former GandCrab affiliate, the group has been linked to numerous ransomware variants including Bad Rabbit, LockBit 2.0, STOP/DJVU, and REvUnspecified
2
Associated Vulnerabilities
To see the evidence that has resulted in these vulnerability associations, create a free account
Alias DescriptionAssociation TypeVotes
The vulnerability Atomic Macos Stealer (Amos is associated with Vidar. Unspecified
2
Source Document References
Information about the Vidar Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securelist
11 days ago
Bitdefender
a month ago
ESET
3 months ago
Unit42
3 months ago
Fortinet
4 months ago
Recorded Future
4 months ago
ESET
4 months ago
ESET
4 months ago
DARKReading
4 months ago
DARKReading
4 months ago
Securityaffairs
5 months ago
Recorded Future
6 months ago
InfoSecurity-magazine
6 months ago
CERT-EU
2 years ago
Flashpoint
10 months ago
InfoSecurity-magazine
7 months ago
Bitdefender
7 months ago
CERT-EU
8 months ago
CERT-EU
8 months ago
CERT-EU
8 months ago