Infostealer
Vidar Stealer
Infostealer
32 detections found
Also known as: Vidar, Vidar Trojan, Vidar Malware
Vidar is a Windows information-stealing trojan first observed in late 2018, derived from the Arkei stealer lineage and sold/rented on dark-web and underground forums for use by a range of threat actors. It is commonly distributed through malvertising, phishing, and cracked-software/pirated-game lures, and targets browser credentials, credit card data, cryptocurrency wallets, and FTP client credentials. No law-enforcement takedown has occurred; Vidar remains actively developed, with a revamped "Vidar 2.0" and Go-based loader/builder frameworks (e.g., "Factory-v3") observed in 2025-2026 campaigns that also abuse stolen code-signing certificates to evade detection.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation — Palo Alto Networks Unit 42
- Vidar Malware: Analysis, Detection, Removal — Huntress