Vidar
- First seen
- 2018-10-01 00:00:00
- Malware type
- credential-stealer, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:24:40
- Profile updated
- 2026-07-07 12:41:02
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
Vidar is a forked malware based on Arkei. It seems this stealer is one of the first that is grabbing information on 2FA Software and Tor Browser.
Detection coverage
- 7 YARA rules
Detection rules
- RUSSIANPANDA_Vidar_DLL_Embedded (yara-rule)
- DITEKSHEN_MALWARE_Win_Vidar (yara-rule)
- SEKOIA_Infostealer_Win_Vidar_Str_Jul22 (yara-rule)
- SEKOIA_Infostealer_Win_Vidar_Strings_Nov23 (yara-rule)
- ARTIFACTDROP_Go_Reflectiveloader_Decryption_Loop (yara-rule)
- CAPE_Vidar (yara-rule)
- CAPE_Vidarold (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- socprime.com — Somnia Malware Detection Uac 0118 Aka Frwl Launches Cyber Attacks Against Organizations In Ukraine Using Enhanced Malware Strains (report)
- cloud.google.com — Unc5537 Snowflake Data Theft Extortion (report)
- CISA — Aa23 320A (report)
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- intel471.com — Privateloader Malware (report)
- go.recordedfuture.com — Cta 2022 0802 (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- CISA — Aa23 320A Scattered Spider (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- logpoint.com — Logpoint Etpr A Comprehensive Overview On Stealer Malware Families 1 (report)
- logpoint.com — Logpoint Etpr A Comprehensive Overview On Stealer Malware Families (report)
- blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
- cloudsek.com — Threat Actors Abuse Ai Generated Youtube Videos To Spread Stealer Malware (report)
- cybereason.com — The Hole In The Bucket Attackers Abuse Bitbucket To Deliver An Arsenal Of Malware (report)
- m4lcode.github.io — Vidar (report)
- fumik0.com — Lets Dig Into Vidar An Arkei Copycat Forked Stealer In Depth Analysis (report)
- isc.sans.edu — 28468 (report)
- isc.sans.edu — 28468 (report)
- ke-la.com — Information Stealers A New Landscape (report)
- medium.com — W1 Feb En Story Of The Week Stealers On The Darkweb 49945A31601D (report)
- fortinet.com — The Year Of The Wiper (report)
- esentire.com — Esentire Threat Intelligence Malware Analysis Batloader (report)