Security News

Cybersecurity news aggregator

HIGH Attacks Dark Reading

Vidar Infostealer Hammers SMBs via Malvertising Campaign

A financially motivated malvertising campaign delivers the Vidar infostealer and XMRig cryptominer by luring victims with ads for cracked software to download password-protected archives. The password protection helps evade email scanning and automated sandboxes, and the malware loader inside steals credentials, cookies, and crypto wallets while mining Monero. The campaign is attributed to an experienced affiliate of the Vidar malware-as-a-service operation.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES ENDPOINT SECURITY REMOTE WORKFORCE THREAT INTELLIGENCE NEWS Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining. Elizabeth Montalbano,Contributing Writer July 8, 2026 4 Min Read SOURCE: BITS AND SPLITS VIA SHUTTERSTOCK Threat actors are targeting consumers and small to midsize businesses (SMBs) globally in a financially motivated malvertising campaign that delivers the Vidar infostealer and cryptomining malware with multifaceted delivery and evasion strategies. Researchers from Palo Alto Networks' Unit 42 uncovered the campaign in April; it lures victims to pages for downloading files that impersonate cracked versions of copyright-protected software, according to a report published July 7. The files delivered, however, are actually password-protected archives that hide a malware loader for dropping and executing both the Vidar infostealer and the open source XMRig cryptominer. Vidar targets browser credentials, cookies, and crypto wallets, while the XMRig mines Monero cryptocurrency. LOADING... While the attack follows a typical playbook for malvertising, the campaign stands out for both its delivery mechanism and evasion strategies, which point to an experienced affiliate of the Vidar malware-as-a-service (MaaS) operation, which primarily operates in the US and Europe, according to Unit 42 threat researchers Bharath Nannaka and Pranay Kumar Chhaparwal. Related:Big Brand Jobs Scam Targets Marketing Pros' Google Accounts "The operator behind this campaign runs a dual-monetization scheme," they wrote in the post. "Criminals sell credentials and session cookies stolen by Vidar stealer on criminal log markets, while XMRig provides passive income from hijacked victim CPU cycles." Meanwhile, an aspect of the malware delivery mechanism — the Factory-v3 framework for MaaS building — also appears to be a side hustle for the operators, acting as "a separate upstream service used by at least two distinct stealer affiliates," the researchers wrote. Vidar and XMRig Attack Flow An attack begins when someone clicks on a malicious online ad for pirated or cracked software, which redirects them to attacker-controlled websites hosting the password-protected archives that masquerade as legitimate software installers. The password protection "appears to be a deliberate choice to bypass email gateway scanning and to prevent automated sandbox detonation without the password," the researchers wrote. It also lends an air of legitimacy to the download that could fool skeptical users. When the victim executes the downloaded file, a Go-based loader launches and performs a series of defense-evasion techniques, including an in-memory Antimalware Scan Interface (AMSI) bypass, before deploying its payloads. The loader leverages the Factory-v3 Go framework, which allows it to generate a unique binary per build, the researchers noted. "For example, we observed 27 unique build UUIDs across 43 samples, defeating hash-based detection," they wrote. Related:'BusySnake' Infostealer Slithers Into Critical Infrastructure Networks The loader also is signed with a fabricated certificate for JustWatch, a streaming TV guide, and uses an unusually large file size via padding with null bytes to evade detection by automated analysis, the researchers added. Once executed, the loader installs Vidar, which harvests browser credentials, cookies, browsing history, autofill data, and cryptocurrency wallet files. Simultaneously, the malware also deploys XMRig, which quietly mines Monero in the background using the victim's CPU. Finally, the loader establishes persistence through Windows Registry Run keys and scheduled tasks to ensure the malware survives system reboots. Fortifying Defenses Against MaaS Attacks The campaign demonstrates how financially motivated threat actors are increasingly combining multiple monetization strategies in a single infection to maximize the value of each successful infection, the researchers noted. This demonstrates the continued evolution of MaaS operations toward more efficient, multistage attack chains, they said. SMBs in particular should be especially careful to defend against attackers' evasion tactics, as they appear "specifically tuned for SMB-grade defenses," observes Denis Calderone, principal and chief technology officer of AI security solution provider Suzu Labs. Related:JadePuffer: The First Complete LLM-Driven Ransomware Attack "Binaries padded to nearly 500MB silently skip past sandbox file-size limits most small organizations never adjust, the fake code-signing certificates lean on recognizable brand names to get users past trust warnings, and the AMSI bypass disables script scanning before any stealer logic even runs," he tells Dark Reading. It's also no surprise that the campaign's monetization model is multifaceted, since the targets are smaller, meaning "extortion alone is going to be less profitable," Calderone adds. To help defenders avoid compromise, Unit 42's report included a list of indicators of compromise (IoCs), such as code-signing info, server addresses, hashes, and file paths. Unit 42 also recommends that organizations enforce strong Microsoft Authenticode chain validation and supplement it with defensive measures such as: certificate serial blocklisting; configuring security tooling to scan files regardless of size; and monitoring for MpClient.dll loading from nonstandard paths. According to the report, strategies for defenders to bolster their security profile against the campaign and others like it include hunting the persistence indicators and file-drop patterns described in the report and immediately blocking outbound connections to all C2 addresses and pool.supportxmr[.]com. About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets Say Yes to AI: Securing Innovation Without Compromise More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Critical Fortinet Flaws Under Active Attack by Jai Vijayan, Contributing Writer DEC 17, 2025 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES F5 BIG-IP Environment Breached by Nation-State Actor by Alexander Culafi OCT 15, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos, Contributing Writer OCT 03, 2025 Editor's Choice CYBERSECURITY OPERATIONS Why Identity Security Is Your Cyber Career Entry Point byKristina Beek JUN 30, 2026 CYBERATTACKS & DATA BREACHES EdTech Attackers Shift From Schools to Their Software Suppliers byArielle Waldman JUN 25, 2026 CYBERSECURITY OPERATIONS Do CISOs Need a Code of Ethics? byDark Reading Editorial Team JUN 24, 2026 Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE LOADING... AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article