Skip to content

Vidar

Vidar Stealer is a commodity Windows information stealer offered through a malware-as-a-service model.

Profile source: Mallory opens in a new tab

Vidar

Family profile

Vidar Stealer is a commodity Windows information stealer offered through a malware-as-a-service model. Originally derived from Arkei code, it has been widely used by financially motivated operators and in targeted espionage activity, including campaigns attributed to UNC7005, also tracked as STORM-2945, which is assessed to have links to the Russian ICE RELIC/APT29 ecosystem. Vidar targets browser-stored credentials, saved passwords, cookies, authenticated session data, browsing and autofill data, payment information, FTP and SSH credentials, cryptocurrency-wallet data, communication and gaming-platform data, cloud credentials and tokens, and selected files from local and removable storage. It can collect Azure CLI profile and token data that support cloud identity reconnaissance and account compromise. Recent versions use multithreaded collection, anti-analysis checks, polymorphic builds, browser-process injection to defeat browser encryption protections, and legitimate browser-related libraries to decrypt protected credentials. Collected data may include screenshots and is commonly packaged and exfiltrated through HTTP-based command-and-control channels; some campaigns use Steam, Telegram, or other legitimate online services as dead-drop resolvers. Vidar is distributed through phishing and conference-themed lures, fraudulent software-download sites, malvertising, search-result poisoning, trojanized archives, cracked-software bundles, and social-engineering campaigns that induce users to execute malicious PowerShell commands. It has also been delivered under popular gaming and AI software themes.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
176 IP / 137 hostnames

Leading locations

  • US74
  • DE50
  • CN27
  • FI27
  • NL24
  • HK13
  • KR9
  • RU8
  • LU6
  • GB4
  • SG4
  • FR3

Leading providers

  • Hetzner Online GmbH45
  • Cloudflare, Inc.38
  • FEMO IT SOLUTIONS LIMITED11
  • Omegatech LTD11
  • CHINA UNICOM China169 Backbone7
  • CTG Server Limited7

Infrastructure traits

  • Hosting 239
  • Anycast 38

Samples

Recent associated samples

Reported operators

Threat actors

17 named in public reporting
UNC7005

UNC7005 distributes information-stealing malware. The group deploys VIDAR for Windows ... disguised as conference companion applications.

Storm-2945

In a broader campaign in late May 2026, attackers used a fake Ukraine-related summit site to distribute browser-information stealers to Windows and macOS users. Windows visitors received VIDAR...

FAKESECURITY

It was also discovered that in early 2020, before distributing the Raccoon stealer, the attackers had distributed samples of another stealer called Vidar.

Scattered Spider

Today, we will discuss one of the more advanced stealers: Vidar. Vidar is a piece of malware originating from the Arkei Stealer but uses new methods to find and direct traffic to the attacker.

Water Minyades

Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.

scat01

We found an interesting connections log from May 2019. The sample was related to the Vidar stealer malware family... we can conclude that the Vidar campaign and the DeathRansom campaign are run by the same actor.

Fox Tempest

The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers.

Storm-3075

The observed campaigns led to collection of payment card data, theft of credentials and access tokens, and delivery of malware including Vidar Stealer, Lumma Stealer, Hijack Loader, and Oyster.

UNC5142

UNC5142 (ClearFake Cluster): Primarily uses the BNB Smart Chain to distribute infostealers such as LUMMAC.V2 and Vidar via compromised WordPress sites.

GOLD HARVEST

GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.

Vanilla Tempest

Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.

Storm-0501

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm 2561

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm-0249

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

EncryptHub

“...HijackLoader malware ... downloads the Vidar infostealer (v9d9d.exe).”

Zestix

...relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.

MITRE ATT&CK

Vidar in ATT&CK

112 distinct techniques

Techniques

112 techniques
T1528 Steal Application Access Token T1036 Masquerading T1204.002 Malicious File T1539 Steal Web Session Cookie T1555.003 Credentials from Web Browsers T1036.005 Match Legitimate Resource Name or Location T1070.004 File Deletion T1566.002 Spearphishing Link T1102.001 Dead Drop Resolver T1176 Software Extensions T1056.003 Web Portal Capture T1070 Indicator Removal T1555 Credentials from Password Stores T1564.003 Hidden Window T1608.006 SEO Poisoning T1566 Phishing T1071 Application Layer Protocol T1562 Impair Defenses T1059.001 PowerShell T1204 User Execution T1564.001 Hidden Files and Directories T1547.001 Registry Run Keys / Startup Folder T1105 Ingress Tool Transfer T1204.003 Malicious Image T1218 System Binary Proxy Execution T1568 Dynamic Resolution T1189 Drive-by Compromise T1588.001 Malware T1041 Exfiltration Over C2 Channel T1560 Archive Collected Data T1027 Obfuscated Files or Information T1608.001 Upload Malware T1082 System Information Discovery T1583.001 Domains T1083 File and Directory Discovery T1071.001 Web Protocols T1552.001 Credentials In Files T1055.001 Dynamic-link Library Injection T1005 Data from Local System T1622 Debugger Evasion T1585.003 Cloud Accounts T1573 Encrypted Channel T1113 Screen Capture T1020 Automated Exfiltration T1497.001 System Checks T1055.002 Portable Executable Injection T1518.001 Security Software Discovery T1087.001 Local Account T1649 Steal or Forge Authentication Certificates T1548 Abuse Elevation Control Mechanism T1059 Command and Scripting Interpreter T1598 Phishing for Information T1583 Acquire Infrastructure T1055.012 Process Hollowing T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1078 Valid Accounts T1497 Virtualization/Sandbox Evasion T1027.002 Software Packing T1574.001 DLL T1059.005 Visual Basic T1132 Data Encoding T1566.001 Spearphishing Attachment T1129 Shared Modules T1218.005 Mshta T1055 Process Injection T1119 Automated Collection T1518 Software Discovery T1656 Impersonation T1140 Deobfuscate/Decode Files or Information T1572 Protocol Tunneling T1552 Unsecured Credentials T1053 Scheduled Task/Job T1589 Gather Victim Identity Information T1560.001 Archive via Utility T1059.007 JavaScript T1614.001 System Language Discovery T1021.001 Remote Desktop Protocol T1012 Query Registry T1567 Exfiltration Over Web Service T1027.013 Encrypted/Encoded File T1486 Data Encrypted for Impact T1090 Proxy T1190 Exploit Public-Facing Application T1218.001 Compiled HTML File T1571 Non-Standard Port T1056 Input Capture T1057 Process Discovery T1090.003 Multi-hop Proxy T1547 Boot or Logon Autostart Execution T1033 System Owner/User Discovery T1007 System Service Discovery T1124 System Time Discovery T1027.007 Dynamic API Resolution T1614 System Location Discovery T1056.001 Keylogging T1548.002 Bypass User Account Control T1562.001 Disable or Modify Tools T1559.001 Component Object Model T1588 Obtain Capabilities T1213 Data from Information Repositories T1555.001 Keychain T1222 File and Directory Permissions Modification T1053.005 Scheduled Task T1573.001 Symmetric Cryptography T1584.006 Web Services T1553.002 Code Signing T1059.006 Python T1588.003 Code Signing Certificates T1027.003 Steganography T1557 Adversary-in-the-Middle T1059.010 AutoHotKey & AutoIT T1059.003 Windows Command Shell

Reporting

Research mentioning Vidar

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 6
Cyber Security News

Vanta Stealer Empties Browser Vaults, Crypto Wallets and Gaming Accounts in Minutes

Researchers detailed Vanta Stealer, a Python-based information-stealing malware for Windows that rapidly collects a wide range of data from infected systems. The malware is packaged with PyInstaller and obscured with multiple PyArmor layers, then uses a modular design that can download a dedicated browser extractor during execution. Reported targets include Chromium-based browsers, stored credentials, cookies, payment data, Discord tokens, Steam, Roblox, Riot Games, Valorant, Minecraft, Telegram Desktop, Mullvad VPN, cryptocurrency wallet files and recovery material, private documents, screenshots, and webcam images. After harvesting data, Vanta Stealer logs the results in Summary.txt, compresses the stolen files into a ZIP archive, and sends the archive with victim metadata to a predefined command-and-control endpoint over HTTP POST. Reporting on the malware said likely delivery methods include phishing attachments, fake installers, cheats, bogus software updates, tampered code repositories, and malicious search ads, and noted that defenders should watch for unusual archive uploads and restrict unapproved software while affected users reset passwords, revoke sessions, and review wallet exposure from a clean device.

Aug 6
Cryptika

Vanta Stealer Empties Browser Vaults, Crypto Wallets and Gaming Accounts in Minutes | Cryptika Cybersecurity

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

Aug 5
The Record Media

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | The Record from Recorded Future News

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.