{
  "family": "vidar",
  "sample_count": 1,
  "category": "advanced_threat",
  "description": "<h3>Executive Summary</h3>\nVidar (also known as Vidar Stealer) is a highly sophisticated, commercially available Information Stealer that emerged in late 2018 as a fork of the infamous Arkei stealer. Sold as Malware-as-a-Service (MaaS) on dark web forums, Vidar is engineered for maximum data extraction. It rapidly harvests user credentials, cryptocurrency wallets, financial data, and system information before exfiltrating the data and (frequently) self-deleting to evade forensic analysis.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nVidar is distributed via a wide array of vectors depending on the purchasing affiliate. Common methods include malicious spam (malspam) campaigns, fake software cracks (e.g., \"KMS Activators\"), disguised installers on torrent sites, and delivery via popular exploit kits like RIG or Fallout.\n\nOnce executed, Vidar initiates a rapid and comprehensive data aggregation routine:\n<ul>\n<li><strong>Browser Targeting:</strong> Vidar aggressively targets nearly all modern web browsers (Chrome, Firefox, Edge, Opera, Brave). It extracts saved passwords, autofill data, credit card numbers, browsing history, and critically, active session cookies (allowing attackers to bypass MFA).</li>\n<li><strong>Wallet Extraction:</strong> The stealer is explicitly designed to locate and steal the `wallet.dat` files and recovery phrases associated with dozens of desktop cryptocurrency wallets (e.g., Bitcoin Core, Electrum, Exodus).</li>\n<li><strong>Application Data:</strong> It harvests credentials from FTP clients (FileZilla), email clients (Thunderbird, Outlook), and secure messaging applications (Telegram, Signal).</li>\n<li><strong>Exfiltration and Evasion:</strong> The stolen data is compiled into a ZIP archive and transmitted to a C2 server (often utilizing Telegram or Mastodon APIs for covert C2 communication). Once exfiltration is complete, Vidar typically deletes its own executable and the temporary archive to hinder incident response.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nA Vidar infection is a critical security breach resulting in immediate, catastrophic data loss. The exfiltrated session cookies and credentials allow attackers to completely hijack the user's digital identity, leading to immediate financial theft and the potential compromise of enterprise network access.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Assume Total Compromise:</strong> Because Vidar steals session cookies, simply changing passwords is insufficient. All active sessions across all web services (M365, Google Workspace, banking portals) must be forcefully terminated, followed by a comprehensive password reset.</li>\n<li><strong>Cryptocurrency Asset Movement:</strong> If the user managed cryptocurrency on the infected machine, those assets must be immediately transferred to a new, secure wallet, as the private keys are now in the hands of the attackers.</li>\n<li><strong>Forensic Analysis:</strong> While Vidar often self-deletes, forensic analysis of network logs (PCAPs) can identify the specific C2 infrastructure used for exfiltration, aiding in the generation of IOCs.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Trojan.Vidar",
    "Spyware.VidarStealer",
    "PWS.Win32.Vidar"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1056.001",
    "T1552.001",
    "T1539",
    "T1048"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T17:00:58Z",
  "type": "Info-stealer",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}