Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2 / Distribution
- Host form
- 40 IP / 4 hostnames
Vidar Stealer is a Windows information-stealing malware family widely used in financially motivated campaigns and commonly offered through the malware-as-a-service ecosystem.
Profile source: Mallory opens in a new tabVidar
Vidar Stealer is a Windows information-stealing malware family widely used in financially motivated campaigns and commonly offered through the malware-as-a-service ecosystem. It is designed to harvest sensitive data from infected hosts, including browser credentials, cookies, browsing history, autofill data, cryptocurrency wallet information, system information, files, and application data such as Telegram and Discord artifacts. Vidar is also notable for functioning as a delivery platform for secondary payloads, allowing operators to deploy additional malware after initial compromise, including remote-access tooling and cryptocurrency miners.
Observed delivery chains show Vidar distributed through malvertising, fake cracked-software downloads, SEO-poisoned lure pages, and ClickFix-style social engineering that tricks users into executing attacker-supplied PowerShell commands. In some campaigns, Vidar has also appeared behind multi-stage loaders and DLL sideloading chains. Recent reporting also describes Go-based Vidar variants used as intermediate stages that retrieve and launch follow-on malware.
On execution, Vidar steals browser-stored secrets and session material, collects wallet-related data, and stages information for exfiltration. In multiple campaigns it has been used to download and execute additional components, making infections potentially broader than simple credential theft. Documented follow-on payloads include TELEPUZ and XMRig, illustrating dual-use monetization through both data theft and cryptomining, as well as modular post-compromise expansion.
Vidar primarily targets Windows systems and has been observed affecting consumers, small and medium-sized businesses, and broader enterprise users worldwide. Distribution patterns indicate heavy use in opportunistic, high-volume criminal operations rather than narrowly targeted intrusions, though the stolen data can later enable account takeover, fraud, and further compromise.
C2 tracking
Derp observations, rolling seven-day window
Samples
27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 5bcc428f37655c7bc16110cc2127c510f66827a382cb1c9fa251b15a7d2c214b 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e 9cd9c0a79450290b1ac0ea3235df6cd68332cc5a426991fa1d53eb7f19ec5a09 Reported operators
UNC5142 (ClearFake Cluster): Primarily uses the BNB Smart Chain to distribute infostealers such as LUMMAC.V2 and Vidar via compromised WordPress sites.
Once activated, this malware frequently drops the notorious Vidar stealer to scrape sensitive data from the host machine.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
Users who downloaded the archives received a loader that silently installed Vidar infostealer on their devices.
Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
“...HijackLoader malware ... downloads the Vidar infostealer (v9d9d.exe).”
...new malware strains such as ... Vidar.
...relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.
MITRE ATT&CK
Reporting
That action downloads a VIDAR-based second stage, which then retrieves the TELEPUZ loader and its main payload, continuing a familiar pattern seen in recent ClickFix malware campaigns.
That action downloads a VIDAR-based second stage, which then retrieves the TELEPUZ loader and its main payload, continuing a familiar pattern seen in recent ClickFix malware campaigns that turn user actions into initial access.
For nearby cleanup patterns, see our guides on ClickFix PowerShell commands, TELEPUZ ClickFix-VIDAR infections, and fileless browser-password stealer activity.
That command can start a VIDAR stage, which then downloads TELEPUZ components for theft, persistence, and remote command execution. In this campaign, VIDAR is not the final event. Elastic observed it fetching a TELEPUZ stager named install.exe and the main payload telepuz.dll.
The payload is a Go variant of the Vidar Stealer, which is known to harvest sensitive data from infected hosts and deploy secondary malware, in this case a stager binary that's responsible for launching TELEPUZ.
Related coverage Vidar Stealer Weaponizes AutoIt and Masqueraded Scripts
In June, Remus, ACRStealer, LummaC2, and Vidar were distributed.
Figure 12: Examples of live Infostealer C2s (such as Vidar and StealC) alongside active ClickFix infrastructure, tracked in real-time within Hudson Rock Threat Feeds.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.