Skip to content

PennyWise

Samples

Recent samples

2 sandbox samples in the Derp library, newest 2 shown

MITRE ATT&CK

PennyWise in ATT&CK

14 distinct techniques

Reporting

Research mentioning PennyWise

May 7
Malpedia

Vidar (Malware Family)

Researchers and incident reports show the Vidar infostealer continuing to mature as a credential- and data-theft platform, with operators rotating backend infrastructure, tightening access to affiliate panels, and masking administration through Tor relays, VPN services, and hosting concentrated in Moldova and Russia. Team Cymru linked the operation to infrastructure including my-odin[.]com and several shifting IP addresses, while newer technical analysis found Vidar using multi-stage PowerShell delivery, process injection, API hooking, scheduled-task persistence, and theft of browser data by intercepting CryptProtectMemory before encryption. The malware targets Windows systems and steals credentials, cookies, autofill data, payment cards, crypto-wallet files, tokens, documents, and screenshots, then exfiltrates the data over encrypted channels. Campaigns tied to Vidar have used increasingly flexible command-and-control discovery and broad distribution channels. Analysts observed samples resolving C2 details dynamically through public profiles on Faceit, Telegram, and Steam, allowing operators to change infrastructure without rebuilding malware. Separate reporting tied Vidar to YouTube lures promoting cracked software and AI-generated tutorial videos, where victims were redirected to fake download sites that delivered stealer payloads. Earlier activity also showed Vidar deployed ahead of GandCrab ransomware, stealing victim data before downloading the encryptor, underscoring its role as both a standalone infostealer and a precursor for wider financially motivated intrusions.

Aug 28
Aryaka

Vidar Infostealer in Action From API Hooking to Covert Data Exfiltration

Aug 25
Gatewatcher

Utilisation de faux profils Steam : Vidar Stealer prend les commandes - Gatewatcher

Nov 30
Medium G0njxa

Approaching stealers devs : a brief interview with Vidar | by g0njxa | Medium

Nov 22
Censys Other

Tracking Vidar Infrastructure with Censys - Censys

Jun 15
Team Cymru

Darth Vidar: The Aesir Strike Back in Latest Cyber World | Team Cymru

May 9
Esentire

eSentire Threat Intelligence Malware Analysis: Vidar Stealer | eSentire

Mar 13
Cloudsek

Threat Actors Abuse AI-Generated Youtube Videos to Spread Stealer Malware | CloudSEK