#vidar — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vidar, aggregated by home.social.
-
Fake GTA 6 Extended Look and demo sites deliver an infostealer
Cybercriminals are exploiting the hype surrounding Grand Theft Auto VI by creating fake Rockstar Games websites that appear in search results offering a GTA 6 demo. These sites impersonate legitimate promotional material for Rockstar's official Extended Look scheduled for August 27 on Netflix. Visitors who click 'Play Now' buttons download gta6_installer.exe, a Vidar infostealer. The malware steals browser-saved passwords, cookies, authenticated sessions, autofill data, and FTP credentials from 19 different browsers including Chrome, Edge, and Firefox. The executable uses legitimate browser binaries in headless mode to access protected data, making credential theft more effective. Stolen session tokens can be reused without triggering two-factor authentication, allowing attackers persistent access even after password changes. The campaign exploited recent GTA 6 leaks that began circulating August 18.
Pulse ID: 6a8d3fe4a1d4c2fb6cd421c2
Pulse Link: https://otx.alienvault.com/pulse/6a8d3fe4a1d4c2fb6cd421c2
Pulse Author: AlienVault
Created: 2026-08-25 07:10:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #Cookies #CyberSecurity #Edge #FireFox #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #Vidar #Word #bot #AlienVault
-
https://app.any.run/tasks/8c61ec50-7b6d-4195-9108-91f4141861b5
https://app.any.run/tasks/14657cfb-4f8b-4b83-bf03-242651567e03
c2 on the #vidar https:// www.figma\.com
-
Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials
Indicators extracted from public reporting. Source: https://telegram.me/share/url?url=https://cybersecuritynews.com/fake-google-gemini-installer/&text=Hackers+Use+Fake+Google+Gemini+Installer+to+Deploy+Vidar+Stealer+and+Steal+Browser+Credentials
Pulse ID: 6a883cd3267d21c3675a3a86
Pulse Link: https://otx.alienvault.com/pulse/6a883cd3267d21c3675a3a86
Pulse Author: CyberHunter_NL
Created: 2026-08-21 11:56:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Telegram #Vidar #bot #CyberHunter_NL
-
Distinct Clusters Target Individuals of Interest to Russia
Three distinct suspected Russian cyber espionage threat clusters—UNC6293, UNC7005, and UNC5976—are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, governments, and think tanks across Europe and the United States. These groups conduct sophisticated phishing campaigns using app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are assessed with moderate confidence to be initial access clusters linked to ICE RELIC (formerly APT29), while UNC5976 appears distinct. Operations leverage social engineering through fake diplomatic invitations, conference registrations, and file sharing pages. UNC7005 was tied to hospitality captive portal redirects and deployed MaaS infostealers including VIDAR and ATOMIC. These actors abuse legitimate authentication mechanisms including Google OAuth, Microsoft device codes, and WhatsApp device linking to compromise personal accounts, making detection challenging for organizations.
Pulse ID: 6a8734bac622f3c7b2d9a633
Pulse Link: https://otx.alienvault.com/pulse/6a8734bac622f3c7b2d9a633
Pulse Author: AlienVault
Created: 2026-08-20 17:09:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT29 #CyberSecurity #Espionage #Europe #FileSharing #Google #Government #Hospital #InfoSec #InfoStealer #MaaS #Malware #Microsoft #OTX #OpenThreatExchange #Password #Phishing #RAT #Russia #SMS #SocialEngineering #UnitedStates #Vidar #WhatsApp #Word #bot #AlienVault
-
How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding
WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...
Pulse ID: 6a7b3ff969397d537e5d24fa
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ff969397d537e5d24fa
Pulse Author: AlienVault
Created: 2026-08-11 15:30:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault
-
Vidar Malware: How the Multithreaded Windows Stealer Works
#Vidar
https://www.picussecurity.com/resource/blog/vidar-malware-how-the-multithreaded-windows-stealer-works -
#clickfix to #vidar (among other things) via:
http:// www\.apcconstruction\.com/
https://app.any.run/tasks/4599dbb0-1041-43f3-b127-a42cfc7ca60e
-
New #GhostShell hacking group is targeting Ukraine’s drone defense sector with fake Besomar-themed documents, spyware, and Vidar malware.
Listen or read: https://hackread.com/ghostshell-hacking-group-ukraine-drone-defense-sector/
-
Fake Software Tutorials on TikTok Spread Vidar Stealer
Threat actors are leveraging TikTok and Instagram Reels to distribute the Vidar infostealer through fake software tutorials. Two distinct campaigns use short-form videos disguised as tutorials for unlocking premium software like Spotify. The first campaign uses accounts mimicking official Windows profiles with AI-voiced clips instructing users to run PowerShell commands that download Vidar from lookalike domains. One video achieved over 100,000 views. The second campaign uses ordinary accounts posting music-backed clips that bait users in comments to receive malicious links via direct message. These campaigns exploit platform recommendation algorithms by encouraging saves and shares. Vidar is sold as a service for $300 lifetime license and harvests credentials, financial data and authentication tokens.
Pulse ID: 6a298f548047c70cc9e2f4ee
Pulse Link: https://otx.alienvault.com/pulse/6a298f548047c70cc9e2f4ee
Pulse Author: AlienVault
Created: 2026-06-10 16:22:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #FinancialData #InfoSec #InfoStealer #Instagram #Mimic #OTX #OpenThreatExchange #PowerShell #Vidar #Windows #bot #AlienVault
-
📣🚨 Watch out as scammers are using TikTok and Instagram Reels tutorials to trick users into running commands that install #Vidar Infostealer.
Read: https://hackread.com/scammers-tiktok-instagram-reels-vidar-infostealer/
#TikTok #Instagram #Reels #Infostealer #Cybersecurity #Malware
-
📢⚠️ New version of Vidar infostealer spreads via fake CAPTCHA, hides in JPEG and TXT files, uses fileless attacks, and steals browser and crypto wallet data.
Read: https://hackread.com/vidar-infostealer-fake-captchas-jpeg-txt-files/
-
It has been a super busy week, and I totally forgot to post photo of the #Vidar after it was finished.
Unfortunately the box for it was crushed a while ago so just a plain background for this one. This is another, like the Leo, I started a long time ago so some gate marks are more visible than others.Currently, I’m working on a HG Wing Zero which should be the next one I post. #gunpla @Gundam #ironbloodedorphans
-
The upgraded version of #Vidar infostealer is being spread via Reddit and GitHub, hidden in fake game cheats for popular titles like Fortnite and Counter-Strike, targeting young gamers.
Read: https://hackread.com/vidar-2-0-infostealer-fake-game-cheats-github-reddit/
#CyberSecurity #Gaming #Infostealer #Fortnite #CounterStrike
-
#OysterLoader (aka #Broomstick or #Cleanup) is not just another downloader. Often serving as a precursor to #Rhysida #ransomware campaigns or distributing commodity malware such as #Vidar, this threat has evolved significantly as we enter 2026.
https://blog.sekoia.io/oysterloader-unmasked-the-multi-stage-evasion-loader/
-
When you finally reverse the loader for that malware sample #VirusTotal flagged as "APT XYZ". and it turns out to be just a #Vidar #Stealer dropper.
4 Stages including Steganography for nothing 😕 -
Vidar Stealer 2.0 Boosts Infostealer’s Credential Theft and Evasion Capabilities https://thecyberexpress.com/vidar-stealer-2-0-infostealer/ #TheCyberExpressNews #ThreatIntelligence #CredentialAttacks #LummaInfostealer #VidarInfostealer #TheCyberExpress #FirewallDaily #infostealer #cybercrime #CyberNews #Lumma #Vidar
-
Vidar Stealer Exploits: Direct Memory Attacks Used to Capture Browser Credentials https://gbhackers.com/vidar-stealer-exploits/ #CyberSecurityNews #cybersecurity #Vidar