Vidar is a Windows information-stealing malware family and malware-as-a-service operation active since 2018. It is widely regarded as a descendant of Arkei and has been used across commodity cybercrime ecosystems as a credential theft and data collection payload. Vidar is commonly delivered by loaders and distribution services such as BatLoader, PrivateLoader, GuLoader, MintsLoader, and other multistage crimeware chains, and it has also been spread through phishing lures, fake document-viewer pages, malicious macro documents, malvertising, SEO-poisoned software download pages, and trojanized or cracked software installers.
Vidar’s core function is theft of sensitive data from infected hosts. High-confidence reporting shows collection of browser-stored credentials, cookies, browsing history, host profiling data, cryptocurrency wallet data, and application data from services such as Telegram, Discord, Steam, and other desktop applications. It can also capture screenshots and use a configurable file grabber to exfiltrate files matching operator-defined criteria. To support browser data theft, Vidar commonly retrieves legitimate browser-related libraries at runtime and uses them to access or decrypt stored data from Chromium-based and Mozilla-based browsers.
The malware operates through a command-and-control-driven configuration model. After execution, the implant contacts its control infrastructure to obtain collection settings, feature flags, and exfiltration parameters. It then stages harvested data locally, often in SQLite-backed structures, and exfiltrates the results as archived data, including Base64-encoded ZIP packaging in observed cases. Anti-analysis behavior has also been documented, including abrupt termination and access-violation behavior in some sandboxed or debugger-assisted environments, which can hinder dynamic analysis and memory forensics.
Vidar is frequently observed as a second-stage payload in broader intrusion chains rather than as a standalone initial access tool. It has appeared in campaigns linked to fake software installers, Google Ads abuse, phishing operations targeting e-commerce administrators, and malware bundles associated with cracked software. Stolen credentials from such infections have been used to enable follow-on compromise, including access to corporate VPNs and administrative panels. Vidar has also been associated with criminal ecosystems overlapping with Magecart-style payment theft operations, and it has been delivered alongside or in rotation with other commodity stealers such as RedLine, Raccoon, FickerStealer, and Lumma.
The malware has been discussed in connection with multiple cybercrime clusters and affiliate-style ecosystems, including operators tied to BatLoader activity and broader financially motivated malware distribution networks. It is also notable for sustained commercial development, frequent updates, and continued popularity among threat actors seeking browser credentials, session material, wallet data, and other monetizable information from Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It was also discovered that in early 2020, before distributing the Raccoon stealer, the attackers had distributed samples of another stealer called Vidar.
Today, we will discuss one of the more advanced stealers: Vidar. Vidar is a piece of malware originating from the Arkei Stealer but uses new methods to find and direct traffic to the attacker.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
We found an interesting connections log from May 2019. The sample was related to the Vidar stealer malware family... we can conclude that the Vidar campaign and the DeathRansom campaign are run by the same actor.
The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers.
The observed campaigns led to collection of payment card data, theft of credentials and access tokens, and delivery of malware including Vidar Stealer, Lumma Stealer, Hijack Loader, and Oyster.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
If the website administrator’s computer was successfully infected, attackers used the administrator’s credentials to obtain access to the admin panel of e-commerce CMS in order to install a JS-sniffer
Potential victims of this malicious campaign received spam email messages containing a link to a 1st-level fake page.
a malicious DOC file with an embedded macro ... drops executable files after editing is enabled
The network activity from the report indicates the sample downloaded mozglue.dll, sqlite3.dll, nss3.dll, freebl3.dll, and a couple others. These DLLs are commonly downloaded and loaded into memory by stealers...
If the victim clicks on this button, they will download a malicious application | Second-level pages contain links to EXE files, which are installed on the victim’s computer after they click on the “ Download plugin ” button.
La technique de téléchargement des DLL dans le répertoire d’exécution du programme malveillant permet donc deux choses : S’assurer que l’environnement du malware est correctement configuré ... ne pas lever d’alerte relative à l’accession ... à des répertoire nécessitant des droits élevés.
crypters, which are also referred to as loaders or packers, are applications designed to encrypt and obfuscate malware to evade detection by antivirus (AV) scanners and hinder analysis.
It's packed with a multistage packer. Following unpacking, we discovered different stealers being delivered from this infrastructure, such as Vidar and FickerStealer.
After unpacking, the payload is executed in memory using reflective loading or Process Hollowing.
If the website administrator’s computer was successfully infected, attackers used the administrator’s credentials to obtain access to the admin panel of e-commerce CMS in order to install a JS-sniffer
This HTML has a button object which automatically triggers the silent re-execution of the .CHM “pss10r.chm” with mshta. Mshta is a Windows binary used for executing HTA files.
nous avons pu identifier que certains mécanismes d’évasion des systèmes d’analyses existaient dans le code.
La technique de téléchargement des DLL dans le répertoire d’exécution du programme malveillant permet donc deux choses : S’assurer que l’environnement du malware est correctement configuré ... ne pas lever d’alerte relative à l’accession ... à des répertoire nécessitant des droits élevés.
Our experts were able to determine that the malware was stealing browser cookies and passwords, along with detailed system information, before sending these to a C2 IP address.
Before it performs info-stealing activities, it connects to C&C server to receive commands and download additional DLL files... Vidar abuses online gaming platforms to actually create C&C server. | When Vidar requests HTTP GET for the URL shown above, it receives the json format data from faceit.com. The malware parses the ‘about’ part in the data, which is the actual URL for the C&C server.
928 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer referenced as an example of malware that can bypass browser protections when operating inside a trusted browser process.
Mentioned only as an unrelated malware family sharing the generic WinRAR SFX stub fingerprint in open-source records.
Vidar is described as targeting browser and wallet data, including saved credentials, cookies, and cryptocurrency-wallet information, and was observed communicating via a Telegram channel, a Steam profile, and a compromised Brazilian website.
A browser and wallet stealer used to collect browser credentials, cryptocurrency wallet data, and session tokens.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.