216.73.217.80

Vidar Stealer: Infostealer malware discovered in Steam game

· Published 07/04/2025 19:41 · Modified 07/04/2025 22:36

Export JSON

Essential information

Published
07/04/2025 19:41
Modified
07/04/2025 22:36
Tags
2025-04-07 bginfo expired signatures gaming platforms information-stealing malware obfuscation thread hijacking vidar stealer
Related entities
1 observables, 1 techniques (mitre), 1 malware

Description

A recent analysis uncovered a sophisticated deployment of , an infamous malware, disguised as a legitimate Microsoft Sysinternals tool, .exe. The malware, found with an expired Microsoft signature, was significantly larger than the original file and contained modified initialization routines. It creates virtual memory allocations to execute its malicious code, ultimately extracting and running . This variant maintains its core functionalities, including credential theft, cryptocurrency wallet targeting, session hijacking, and cloud data theft. The incident highlights the evolving tactics of cybercriminals, emphasizing the need for vigilant threat hunting and proactive security measures.

External references