Vidar is a Windows information-stealing malware family first observed in late 2018. It is sold as a customizable malware-as-a-service offering and is primarily implemented in C++. Vidar harvests browser passwords, cookies, session data, browsing history, cryptocurrency wallet files, sensitive local documents, and application data, including Telegram information. Stolen credentials and session artifacts support account takeover, while wallet theft exposes cryptocurrency assets. Its victims include individual users and employees whose infected devices contain corporate credentials; observed operators include UNC5587.
Vidar is distributed through multistage infection chains, including ClickFix lures on compromised websites that persuade users to execute malicious commands. Malware loaders, including SmokeLoader and 2CLoader, also deliver it. Vidar has been observed alongside STOP/Djvu ransomware. After execution, it collects sensitive data, stages it locally, and exfiltrates it to remote command-and-control infrastructure. Telegram and Steam profile content can supply command-and-control addresses, allowing operators to change destinations without rebuilding the malware.
Vidar uses process injection, including execution within a suspended legitimate Windows process, and observed variants create remote threads in browser processes. Its evasion techniques include debugger and analysis-environment detection, string obfuscation, and deletion of staged data after exfiltration. During 2026, its string protection evolved from XOR-based obfuscation to ChaCha20 and subsequently to a custom bytecode interpreter combined with a build-specific stream cipher. These changes complicate static detection and reverse engineering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Vidar is a well-known infostealer malware family designed to harvest sensitive data from infected systems, especially from browsers and crypto wallets.
CVE-2024-1709 (CWE-288) — Authentication Bypass Using Alternate Path or Channel. Base CVSS score of 10, indicating “Critical”.
CVE-2024-1708 (CWE-22) — Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”). Base CVSS score of 8.4, still considered “High Priority”.
In one campaign analyzed by CTM360, threat actors have been observed leveraging known vulnerabilities in WordPress plugins (e.g., CVE-2026-6854) to seize control of websites and inject ClickFix lures. More than 3,000 actively compromised websites have been identified as hosting fake pages, with the attack chains leading to Vidar Stealer.
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor, tracked by Mandiant as UNC5587, used infostealer malware such as RedLine, Lumma, and Vidar to harvest credentials from infected employee devices.
UNC7005 distributes information-stealing malware. The group deploys VIDAR for Windows ... disguised as conference companion applications.
In a broader campaign in late May 2026, attackers used a fake Ukraine-related summit site to distribute browser-information stealers to Windows and macOS users. Windows visitors received VIDAR...
It was also discovered that in early 2020, before distributing the Raccoon stealer, the attackers had distributed samples of another stealer called Vidar.
Today, we will discuss one of the more advanced stealers: Vidar. Vidar is a piece of malware originating from the Arkei Stealer but uses new methods to find and direct traffic to the attacker.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Les identifiants ciblés comprennent clés IAM, jetons OIDC, jetons Entra ID, comptes de service GCP, PATs et clés API; la liste inclut T1078 — Valid Accounts.
Behind the overlay, the malicious JavaScript silently wrote a heavily obfuscated PowerShell command to the user’s clipboard.
It executes process injection by writing the virtual memory of the suspended process RegAsm.exe with code retrieved from the decoded .data section.
Vidar moved from basic XOR encryption and altered ChaCha20 routines to a custom virtual machine and stream cipher that vary with every build, hiding strings that reveal commands, configuration, error messages, and intended actions.
The virtual machine can directly reveal a string, or recover a key and nonce used to unlock a second encrypted data block. Vidar also uses modified ChaCha-based and add-rotate-XOR stream-cipher designs across versions.
The opcodes, constants and lookup tables can change in every build... Vidar keeps the same job while changing the small details that a detection rule may expect.
A fake Gemini installer campaign showed how a trusted-looking download can lead to browser-password theft, while fake YouTube software downloads have also been used to reach employees.
It executes process injection by writing the virtual memory of the suspended process RegAsm.exe with code retrieved from the decoded .data section.
Les identifiants ciblés comprennent clés IAM, jetons OIDC, jetons Entra ID, comptes de service GCP, PATs et clés API; la liste inclut T1078 — Valid Accounts.
“A valid token can open cloud consoles, code repositories, build pipelines, and AI services” and “criminals buy access rather than exploit flaws.”
It proceeds to decode the content of the .data section using bitwise XOR operations.
Les cibles incluent des jetons OIDC AWS SSO, jetons Entra ID et refresh tokens, jetons GCP, GitHub App/OAuth/PAT, jetons GitLab Runner et jetons OAuth d’outils IA.
“If malware steals that token and an attacker loads it into another browser, the service may treat the attacker as the authenticated user.” The listed targets include GitHub and ChatGPT browser-session cookies.
Vidar has spent years stealing the data people keep closest: saved passwords, browser cookies, wallet files and system details.
It also attempts to read system-specific directories ... such as $Recycle.Bin, $Windows.~BT, $SysReset using ReadFile operation.
1,047 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another prevalent information-stealer family for comparison with Warden Stealer, not as a component of the Warden infection chain.
Information-stealer family mentioned as a prevalence comparison with Warden Stealer, not as part of the reported Warden infection chain.
Mentioned as another prevalent infostealer and as a technical comparison for Warden Stealer's Application-Bound Encryption bypass. Its described approach scans browser memory for Chromium KeyRing entries using a 32-byte signature.
Listed as an information-stealing payload associated with ClickFix social engineering, which persuades users to execute malicious commands under the guise of troubleshooting. No Vidar-specific behavior or campaign is described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.