EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/criminal-hacking/vidar-stealer
227/430

File EL-0204HighColdCriminal Hacking / Credential Theft / InfoStealer

Vidar Stealer

Also filed as Vidar Malware · Vidar Stealer Malware

Vidar Stealer is a type of info-stealer malware designed to compromise endpoints and exfiltrate sensitive data. It targets credentials, browser data, and other personal information stored on infected systems. The malware is typically distributed through phishing campaigns or exploiting vulnerabilities in common software.

  • #stealer
  • #credential-theft
  • #malware
  • #info-stealer
  • #vidar
Notoriety6/10
Event
1 Jan 2018
Disclosed
1 Jan 2018
Target
Global End Users
Actor
Vidar Operators
Scale
Variable (depends on system data)
Status
Cold

01Summary

The Vidar Stealer malware operates by establishing persistence on a compromised machine and systematically harvesting various forms of stored data. Its primary targets include saved passwords from web browsers, session cookies, cryptocurrency wallet keys, and stored API tokens. Unlike some single-purpose stealers, Vidar often employs modular components, allowing it to adapt to different operating systems and security environments. The data collected is then packaged and exfiltrated to a remote command-and-control (C2) server, where it is sold on underground marketplaces. The threat's evolution reflects the increasing monetization of stolen digital identities.

02Background

Info-stealers have become a primary vector for cybercrime, moving away from simple ransomware to focus on high-value, non-destructive data theft. Vidar emerged during a period of heightened focus on digital identity theft, capitalizing on the widespread use of cloud services and online accounts. Its existence highlights the persistent vulnerability of user-managed credentials.

03Key revelations

  1. 01The ability to harvest credentials from multiple, disparate sources (browsers, crypto wallets).
  2. 02The modular design allows for rapid adaptation to new operating systems and security patches.
  3. 03The primary goal is the sale of high-value, actionable identity data on underground markets.

04Technical analysis

Vidar Stealer typically utilizes memory scraping techniques and API calls to access data stored by legitimate applications. It often injects into running processes to bypass basic endpoint detection. The malware payload is designed to be highly portable, making it effective across Windows, macOS, and Linux environments, although specific implementations may vary.

Attack vector
Phishing emails, malicious downloads, compromised websites (watering holes)
Attack method
Credential harvesting and data exfiltration
Initial access
Phishing/Malicious Payload Delivery
Lateral movement
None (Endpoint focused)
Persistence
Registry modification, Scheduled Tasks
Exfiltration
HTTP/S POST requests to C2 infrastructure
Tool / malware
Vidar Stealer
Malware family
Info-stealer
Malware type
Stealer

MITRE ATT&CK techniques

  • T1056.001
  • T1566.001

05Threat actor

The Vidar Operators are characterized as a highly organized, financially motivated criminal group. They operate with a professional structure, suggesting a business model where data is harvested, processed, and sold to the highest bidder on dark web forums.

Aliases

  • Unknown Cybercrime Group

MITRE groups

  • T1056.001
  • T1566.001

Attribution sources

  • Security Vendors

06Victims and impact

Additional victims

  • Corporate Networks

Countries affected

  • Global

07Data exposed

Data types

  • credentials
  • passwords
  • session cookies
  • API keys
  • PII

08Financial damage

Damage is estimated based on the cost of identity theft and corporate breach remediation.

09Timeline

  1. 2018-01-01Initial detection and public reporting of the Vidar Stealer threat.

10Reaction and fallout

Public reaction

The public reaction has been one of increased caution regarding online credentials and the necessity of using multi-factor authentication (MFA). Security awareness campaigns have intensified.

Political impact

The threat underscores the need for global cooperation in cybersecurity standards, particularly concerning endpoint security and data protection laws like GDPR.

11Legal

No specific legal outcome is documented for the operators, but the incident contributed to increased focus on cybercrime legislation globally.

Civil lawsuits

  • Class-action lawsuits against service providers due to data breaches

12Aftermath

Policy changes

  • Increased adoption of password managers and hardware security keys (e.g., YubiKey)

Regulatory changes

  • Stricter enforcement of data breach notification laws (e.g., GDPR)

Security improvements

  • Mandatory implementation of Multi-Factor Authentication (MFA)
  • Enhanced endpoint detection and response (EDR) solutions

13Significance and legacy

Significance

Vidar Stealer exemplifies the shift in cybercrime from destructive attacks (like wipers) to highly profitable, non-destructive data theft. It represents a mature, professionalized criminal enterprise focused purely on the monetization of digital identity, making it a benchmark for modern info-stealers.

Legacy

The malware's existence accelerated the industry shift toward behavioral biometrics and hardware-backed security keys, making simple password theft significantly harder. It solidified the 'info-stealer' category as a major threat vector.

14Disclosure and media

Authentication
Malware Analysis

Media partners

  • Security Research Firms

Publishing organisations

  • Security Vendors

15Field notes

  1. 01The modular nature of the malware allows it to be updated frequently to bypass specific security product signatures.
  2. 02Vidar often targets cryptocurrency wallets because the keys represent immediate, high-value liquid assets.

16Resolution

The threat remains active and evolves, but specific versions are frequently analyzed and mitigated by security vendors.

17Sources

Official documents

  • Vendor Threat Reports

References

  1. [1]Mandiant Reports
  2. [2]CrowdStrike Intelligence
Fact sheetEL-0204

Dates

Event
1 Jan 2018
Started
1 Jan 2018
Discovered
1 Jan 2018
Disclosed
1 Jan 2018
Ongoing
No

Target

Organisation
Global End Users
Type
Individual
Sector
General Consumer
Country
Global

Actor

Name
Vidar Operators
Type
Criminal Gang
Motivation
Financial gain through credential theft and data sale
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

Volume
Variable (depends on system data)
Sensitivity
Confidential
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.