Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 176 IP / 137 hostnames
Vidar Stealer is a commodity Windows information stealer offered through a malware-as-a-service model.
Profile source: Mallory opens in a new tabVidar
Vidar Stealer is a commodity Windows information stealer offered through a malware-as-a-service model. Originally derived from Arkei code, it has been widely used by financially motivated operators and in targeted espionage activity, including campaigns attributed to UNC7005, also tracked as STORM-2945, which is assessed to have links to the Russian ICE RELIC/APT29 ecosystem. Vidar targets browser-stored credentials, saved passwords, cookies, authenticated session data, browsing and autofill data, payment information, FTP and SSH credentials, cryptocurrency-wallet data, communication and gaming-platform data, cloud credentials and tokens, and selected files from local and removable storage. It can collect Azure CLI profile and token data that support cloud identity reconnaissance and account compromise. Recent versions use multithreaded collection, anti-analysis checks, polymorphic builds, browser-process injection to defeat browser encryption protections, and legitimate browser-related libraries to decrypt protected credentials. Collected data may include screenshots and is commonly packaged and exfiltrated through HTTP-based command-and-control channels; some campaigns use Steam, Telegram, or other legitimate online services as dead-drop resolvers. Vidar is distributed through phishing and conference-themed lures, fraudulent software-download sites, malvertising, search-result poisoning, trojanized archives, cracked-software bundles, and social-engineering campaigns that induce users to execute malicious PowerShell commands. It has also been delivered under popular gaming and AI software themes.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f1af10b96c08c9aeecf28c2fa238542e667d218df65ce51701aaaeb7dcc75b1 16168cc3b16d768beffaf0fd10f74f86f79da7a2c7ca26edd91c09c1c101811d 398da2e951f8287d6aa7e53c1c9c0748a5c39af3353b8af94020036fcb9d5bef 97fdbb5506534af805db9e23503d93439322650eeaba8132c2627d8a1b9c2dfb baa739eba49601b21067818ff725e168894a0c186e90405180687cb26970f89a 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef Reported operators
UNC7005 distributes information-stealing malware. The group deploys VIDAR for Windows ... disguised as conference companion applications.
In a broader campaign in late May 2026, attackers used a fake Ukraine-related summit site to distribute browser-information stealers to Windows and macOS users. Windows visitors received VIDAR...
It was also discovered that in early 2020, before distributing the Raccoon stealer, the attackers had distributed samples of another stealer called Vidar.
Today, we will discuss one of the more advanced stealers: Vidar. Vidar is a piece of malware originating from the Arkei Stealer but uses new methods to find and direct traffic to the attacker.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
We found an interesting connections log from May 2019. The sample was related to the Vidar stealer malware family... we can conclude that the Vidar campaign and the DeathRansom campaign are run by the same actor.
The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers.
The observed campaigns led to collection of payment card data, theft of credentials and access tokens, and delivery of malware including Vidar Stealer, Lumma Stealer, Hijack Loader, and Oyster.
UNC5142 (ClearFake Cluster): Primarily uses the BNB Smart Chain to distribute infostealers such as LUMMAC.V2 and Vidar via compromised WordPress sites.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
“...HijackLoader malware ... downloads the Vidar infostealer (v9d9d.exe).”
...new malware strains such as ... Vidar.
...relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.
MITRE ATT&CK
Reporting
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Researchers detailed Vanta Stealer, a Python-based information-stealing malware for Windows that rapidly collects a wide range of data from infected systems. The malware is packaged with PyInstaller and obscured with multiple PyArmor layers, then uses a modular design that can download a dedicated browser extractor during execution. Reported targets include Chromium-based browsers, stored credentials, cookies, payment data, Discord tokens, Steam, Roblox, Riot Games, Valorant, Minecraft, Telegram Desktop, Mullvad VPN, cryptocurrency wallet files and recovery material, private documents, screenshots, and webcam images. After harvesting data, Vanta Stealer logs the results in Summary.txt, compresses the stolen files into a ZIP archive, and sends the archive with victim metadata to a predefined command-and-control endpoint over HTTP POST. Reporting on the malware said likely delivery methods include phishing attachments, fake installers, cheats, bogus software updates, tampered code repositories, and malicious search ads, and noted that defenders should watch for unusual archive uploads and restrict unapproved software while affected users reset passwords, revoke sessions, and review wallet exposure from a clean device.
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.