home.social

#vidar — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vidar, aggregated by home.social.

fetched live
  1. Fake GTA 6 Extended Look and demo sites deliver an infostealer

    Cybercriminals are exploiting the hype surrounding Grand Theft Auto VI by creating fake Rockstar Games websites that appear in search results offering a GTA 6 demo. These sites impersonate legitimate promotional material for Rockstar's official Extended Look scheduled for August 27 on Netflix. Visitors who click 'Play Now' buttons download gta6_installer.exe, a Vidar infostealer. The malware steals browser-saved passwords, cookies, authenticated sessions, autofill data, and FTP credentials from 19 different browsers including Chrome, Edge, and Firefox. The executable uses legitimate browser binaries in headless mode to access protected data, making credential theft more effective. Stolen session tokens can be reused without triggering two-factor authentication, allowing attackers persistent access even after password changes. The campaign exploited recent GTA 6 leaks that began circulating August 18.

    Pulse ID: 6a8d3fe4a1d4c2fb6cd421c2
    Pulse Link: otx.alienvault.com/pulse/6a8d3
    Pulse Author: AlienVault
    Created: 2026-08-25 07:10:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #Cookies #CyberSecurity #Edge #FireFox #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #Vidar #Word #bot #AlienVault

  2. Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

    Indicators extracted from public reporting. Source: telegram.me/share/url?url=http

    Pulse ID: 6a883cd3267d21c3675a3a86
    Pulse Link: otx.alienvault.com/pulse/6a883
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 11:56:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Telegram #Vidar #bot #CyberHunter_NL

  3. Distinct Clusters Target Individuals of Interest to Russia

    Three distinct suspected Russian cyber espionage threat clusters—UNC6293, UNC7005, and UNC5976—are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, governments, and think tanks across Europe and the United States. These groups conduct sophisticated phishing campaigns using app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are assessed with moderate confidence to be initial access clusters linked to ICE RELIC (formerly APT29), while UNC5976 appears distinct. Operations leverage social engineering through fake diplomatic invitations, conference registrations, and file sharing pages. UNC7005 was tied to hospitality captive portal redirects and deployed MaaS infostealers including VIDAR and ATOMIC. These actors abuse legitimate authentication mechanisms including Google OAuth, Microsoft device codes, and WhatsApp device linking to compromise personal accounts, making detection challenging for organizations.

    Pulse ID: 6a8734bac622f3c7b2d9a633
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:09:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT29 #CyberSecurity #Espionage #Europe #FileSharing #Google #Government #Hospital #InfoSec #InfoStealer #MaaS #Malware #Microsoft #OTX #OpenThreatExchange #Password #Phishing #RAT #Russia #SMS #SocialEngineering #UnitedStates #Vidar #WhatsApp #Word #bot #AlienVault

  4. How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding

    WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...

    Pulse ID: 6a7b3ff969397d537e5d24fa
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:30:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault

  5. Fake Software Tutorials on TikTok Spread Vidar Stealer

    Threat actors are leveraging TikTok and Instagram Reels to distribute the Vidar infostealer through fake software tutorials. Two distinct campaigns use short-form videos disguised as tutorials for unlocking premium software like Spotify. The first campaign uses accounts mimicking official Windows profiles with AI-voiced clips instructing users to run PowerShell commands that download Vidar from lookalike domains. One video achieved over 100,000 views. The second campaign uses ordinary accounts posting music-backed clips that bait users in comments to receive malicious links via direct message. These campaigns exploit platform recommendation algorithms by encouraging saves and shares. Vidar is sold as a service for $300 lifetime license and harvests credentials, financial data and authentication tokens.

    Pulse ID: 6a298f548047c70cc9e2f4ee
    Pulse Link: otx.alienvault.com/pulse/6a298
    Pulse Author: AlienVault
    Created: 2026-06-10 16:22:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #FinancialData #InfoSec #InfoStealer #Instagram #Mimic #OTX #OpenThreatExchange #PowerShell #Vidar #Windows #bot #AlienVault

  6. 📣🚨 Watch out as scammers are using TikTok and Instagram Reels tutorials to trick users into running commands that install #Vidar Infostealer.

    Read: hackread.com/scammers-tiktok-i

    #TikTok #Instagram #Reels #Infostealer #Cybersecurity #Malware

  7. 📢⚠️ New version of Vidar infostealer spreads via fake CAPTCHA, hides in JPEG and TXT files, uses fileless attacks, and steals browser and crypto wallet data.

    Read: hackread.com/vidar-infostealer

    #Vidar #Infostealer #Malware #Crypto #ClickFix

  8. It has been a super busy week, and I totally forgot to post photo of the #Vidar after it was finished.
    Unfortunately the box for it was crushed a while ago so just a plain background for this one. This is another, like the Leo, I started a long time ago so some gate marks are more visible than others.

    Currently, I’m working on a HG Wing Zero which should be the next one I post. #gunpla @Gundam #ironbloodedorphans

  9. The upgraded version of #Vidar infostealer is being spread via Reddit and GitHub, hidden in fake game cheats for popular titles like Fortnite and Counter-Strike, targeting young gamers.

    Read: hackread.com/vidar-2-0-infoste

    #CyberSecurity #Gaming #Infostealer #Fortnite #CounterStrike

  10. #OysterLoader (aka #Broomstick or #Cleanup) is not just another downloader. Often serving as a precursor to #Rhysida #ransomware campaigns or distributing commodity malware such as #Vidar, this threat has evolved significantly as we enter 2026.

    blog.sekoia.io/oysterloader-un

    #Reverse

  11. When you finally reverse the loader for that malware sample #VirusTotal flagged as "APT XYZ". and it turns out to be just a #Vidar #Stealer dropper.
    4 Stages including Steganography for nothing 😕