Vidar is a Windows infostealer offered as a malware-as-a-service operation and widely used in cybercrime campaigns. It is designed to harvest credentials, browser data, financial information, session material, and cryptocurrency-related assets from infected systems. Vidar commonly relies on runtime string decryption and dynamic API resolution to hinder analysis, and observed samples resolve Windows, WinINet, cryptographic, GDI/GDI+, COM, registry, and SQLite functions during execution.
Its collection scope is broad. Vidar targets Chromium- and Firefox-family browsers to extract saved passwords, cookies, autofill records, browsing history, downloads, and stored payment-card data. It can decrypt protected browser secrets using Windows cryptographic APIs and Mozilla NSS routines. It also targets desktop applications and artifacts associated with FTP clients, messaging platforms, gaming platforms, and cryptocurrency use, including wallet applications and browser-extension wallets. Observed functionality also supports theft of Discord and Telegram artifacts and collection of Steam-related data.
Vidar performs host profiling to enrich stolen data with system metadata such as machine identifiers, hardware profile information, user and computer names, locale, keyboard layouts, timezone, processor, memory, display characteristics, and other environment details. Samples have also shown capabilities consistent with filesystem traversal, process enumeration, screenshot capture, and staging collected information for exfiltration.
Vidar is frequently delivered through other malware or social-engineering-driven infection chains. Observed distribution includes loader-based delivery, malicious websites, and social-media lures masquerading as free or premium software, including fake tutorial videos that induce victims to run commands or download trojanized installers. It has been seen as a follow-on payload from BATLOADER and in broader crimeware ecosystems alongside families such as RedLine Stealer and Ursnif/ISFB.
The malware primarily targets Windows endpoints and is associated with credential theft, session hijacking through cookie and token theft, reconnaissance, and exfiltration. Its emphasis on browser secrets, financial data, and cryptocurrency wallets has made it a common precursor to account compromise, fraud, and downstream intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
These accounts post professional tutorial videos with AI-generated voice overs, walking users through typing a specific PowerShell command that supposedly unlocks Spotify Premium for free. That command instructs Windows to silently download and run a script from a remote address.
Next, vidar will use the GetProcAddress function to get the addresses of all the APIs it uses during execution.
Decrypted string: SELECT name, value FROM autofill ... SELECT name_on_card, expiration_month, expiration_year, card_number_encrypted FROM credit_cards
Decrypted string: RegOpenKeyExA ... RegQueryValueExA ... RegOpenKeyExW ... RegGetValueW ... RegEnumKeyExA ... RegGetValueA ... SOFTWARE\monero-project\monero-core
Decrypted strings enumerate numerous wallet, browser, Telegram, Discord, Steam, FileZilla, WinSCP, Thunderbird, and Authy paths such as \Telegram Desktop\, \discord\, \WalletWasabi\Client\Wallets\, wallet.dat
Decrypted string: SELECT name, value FROM autofill ... SELECT name_on_card, expiration_month, expiration_year, card_number_encrypted FROM credit_cards
BATLOADER will then attempt to download further payloads to the infected machine, such as VidarStealer, Ursnif/ISFB and Redline Stealer, as well as legitimate tooling such as the system management tool NSudo and the Syncro remote monitoring and management (RMM) tool.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer offered as a service that steals login credentials, financial data, and session tokens from infected devices. In this campaign, it is delivered via fake software tutorial videos on TikTok and Instagram Reels that trick users into executing malicious PowerShell commands or downloading fake premium software.
Mentioned as other malware or loader activity related to LaplasClipper executions.
Referenced only in related content as a stealer malware family.
Stealer payload mentioned as one of several malware families BATLOADER may download during infection chains discussed in the report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.