Skip to content
Malware family Windows

Vidar

Vidar Stealer is a Windows information-stealing malware family widely used in financially motivated campaigns and commonly offered through the malware-as-a-service ecosystem.

Profile source: Mallory opens in a new tab

Vidar

Family profile

Vidar Stealer is a Windows information-stealing malware family widely used in financially motivated campaigns and commonly offered through the malware-as-a-service ecosystem. It is designed to harvest sensitive data from infected hosts, including browser credentials, cookies, browsing history, autofill data, cryptocurrency wallet information, system information, files, and application data such as Telegram and Discord artifacts. Vidar is also notable for functioning as a delivery platform for secondary payloads, allowing operators to deploy additional malware after initial compromise, including remote-access tooling and cryptocurrency miners.

Observed delivery chains show Vidar distributed through malvertising, fake cracked-software downloads, SEO-poisoned lure pages, and ClickFix-style social engineering that tricks users into executing attacker-supplied PowerShell commands. In some campaigns, Vidar has also appeared behind multi-stage loaders and DLL sideloading chains. Recent reporting also describes Go-based Vidar variants used as intermediate stages that retrieve and launch follow-on malware.

On execution, Vidar steals browser-stored secrets and session material, collects wallet-related data, and stages information for exfiltration. In multiple campaigns it has been used to download and execute additional components, making infections potentially broader than simple credential theft. Documented follow-on payloads include TELEPUZ and XMRig, illustrating dual-use monetization through both data theft and cryptomining, as well as modular post-compromise expansion.

Vidar primarily targets Windows systems and has been observed affecting consumers, small and medium-sized businesses, and broader enterprise users worldwide. Distribution patterns indicate heavy use in opportunistic, high-volume criminal operations rather than narrowly targeted intrusions, though the stolen data can later enable account takeover, fraud, and further compromise.

Capabilities

  • Credential Theft
  • Exfiltration
  • Post Exploitation
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 20, 2026
Feed role
C2 / Distribution
Host form
40 IP / 4 hostnames

Leading locations

  • DE23
  • FI7
  • FR5
  • NL2
  • US2
  • CH1
  • LU1

Leading providers

  • Hetzner Online GmbH28
  • AEZA GROUP LLC5
  • FEMO IT SOLUTIONS LIMITED2
  • Akamai Connected Cloud1
  • Cloudflare, Inc.1
  • DEDIK SERVICES LIMITED1

Infrastructure traits

  • Hosting 40
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

12 named in public reporting
UNC5142

UNC5142 (ClearFake Cluster): Primarily uses the BNB Smart Chain to distribute infostealers such as LUMMAC.V2 and Vidar via compromised WordPress sites.

Storm-3075

Once activated, this malware frequently drops the notorious Vidar stealer to scrape sensitive data from the host machine.

Scattered Spider

GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.

GOLD HARVEST

GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.

Fox Tempest

Users who downloaded the archives received a loader that silently installed Vidar infostealer on their devices.

Vanilla Tempest

Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.

Storm-0501

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm 2561

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm-0249

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

EncryptHub

“...HijackLoader malware ... downloads the Vidar infostealer (v9d9d.exe).”

Zestix

...relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.

MITRE ATT&CK

Vidar in ATT&CK

98 distinct techniques

Techniques

98 techniques
T1059.001 PowerShell T1564.001 Hidden Files and Directories T1204 User Execution T1070.004 File Deletion T1105 Ingress Tool Transfer T1036 Masquerading T1218.011 Rundll32 T1566 Phishing T1555 Credentials from Password Stores T1027 Obfuscated Files or Information T1053.005 Scheduled Task T1033 System Owner/User Discovery T1083 File and Directory Discovery T1562 Impair Defenses T1497 Virtualization/Sandbox Evasion T1071 Application Layer Protocol T1497.001 System Checks T1608.006 SEO Poisoning T1059 Command and Scripting Interpreter T1564 Hide Artifacts T1140 Deobfuscate/Decode Files or Information T1195 Supply Chain Compromise T1102.001 Dead Drop Resolver T1560 Archive Collected Data T1204.002 Malicious File T1649 Steal or Forge Authentication Certificates T1041 Exfiltration Over C2 Channel T1189 Drive-by Compromise T1539 Steal Web Session Cookie T1562.001 Disable or Modify Tools T1553.002 Code Signing T1583 Acquire Infrastructure T1053 Scheduled Task/Job T1547.001 Registry Run Keys / Startup Folder T1132 Data Encoding T1567 Exfiltration Over Web Service T1059.005 Visual Basic T1027.007 Dynamic API Resolution T1566.002 Spearphishing Link T1071.001 Web Protocols T1055 Process Injection T1564.003 Hidden Window T1055.012 Process Hollowing T1620 Reflective Code Loading T1622 Debugger Evasion T1218.009 Regsvcs/Regasm T1614 System Location Discovery T1082 System Information Discovery T1057 Process Discovery T1574.001 DLL T1102 Web Service T1528 Steal Application Access Token T1012 Query Registry T1113 Screen Capture T1025 Data from Removable Media T1185 Browser Session Hijacking T1543 Create or Modify System Process T1218 System Binary Proxy Execution T1059.003 Windows Command Shell T1568 Dynamic Resolution T1518 Software Discovery T1543.003 Windows Service T1005 Data from Local System T1560.001 Archive via Utility T1555.003 Credentials from Web Browsers T1056 Input Capture T1566.001 Spearphishing Attachment T1573 Encrypted Channel T1568.001 Fast Flux DNS T1003 OS Credential Dumping T1055.004 Asynchronous Procedure Call T1115 Clipboard Data T1218.005 Mshta T1598 Phishing for Information T1078 Valid Accounts T1586.003 Cloud Accounts T1059.006 Python T1593 Search Open Websites/Domains T1587.001 Malware T1588.001 Malware T1583.001 Domains T1204.004 Malicious Copy and Paste T1588.005 Exploits T1584.006 Web Services T1552.002 Credentials in Registry T1124 System Time Discovery T1020 Automated Exfiltration T1112 Modify Registry T1221 Template Injection T1119 Automated Collection T1006 Direct Volume Access T1027.002 Software Packing T1552 Unsecured Credentials T1559 Inter-Process Communication T1553 Subvert Trust Controls T1497.003 Time Based Checks T1106 Native API T1489 Service Stop

Reporting

Research mentioning Vidar

Jul 20
Cyber Security News

ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

That action downloads a VIDAR-based second stage, which then retrieves the TELEPUZ loader and its main payload, continuing a familiar pattern seen in recent ClickFix malware campaigns.

Jul 20
Cryptika

ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands | Cryptika Cybersecurity

That action downloads a VIDAR-based second stage, which then retrieves the TELEPUZ loader and its main payload, continuing a familiar pattern seen in recent ClickFix malware campaigns that turn user actions into initial access.

Jul 17
Trojan Killer News

ACR Stealer ClickFix Campaign Uses WebDAV and MSHTA

For nearby cleanup patterns, see our guides on ClickFix PowerShell commands, TELEPUZ ClickFix-VIDAR infections, and fileless browser-password stealer activity.

Jul 16
Trojan Killer News

TELEPUZ Malware Spreads Through ClickFix-VIDAR Chain

That command can start a VIDAR stage, which then downloads TELEPUZ components for theft, persistence, and remote command execution. In this campaign, VIDAR is not the final event. Elastic observed it fetching a TELEPUZ stager named install.exe and the main payload telepuz.dll.

Jul 16
The Hacker News

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

The payload is a Go variant of the Vidar Stealer, which is known to harvest sensitive data from infected hosts and deploy secondary malware, in this case a stager binary that's responsible for launching TELEPUZ.

Jul 16
Security Online Info

Albiriox Malware Hits Italy via Fake Banking Rewards

Related coverage Vidar Stealer Weaponizes AutoIt and Masqueraded Scripts

Jul 14
Ahnlab Asec

June 2026 Infostealer Trend Report - ASEC

In June, Remus, ACRStealer, LummaC2, and Vidar were distributed.

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Figure 12: Examples of live Infostealer C2s (such as Vidar and StealC) alongside active ClickFix infrastructure, tracked in real-time within Hudson Rock Threat Feeds.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.