Netskope Threat Labs

Vidar

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Vidar is an information stealer sold as a subscription service that targets credentials, browser data, and cryptocurrency wallets on infected systems. Its operators distribute it through phishing, fake software downloads, and loader chains, and its regular updates add evasion and collection features. The family shares infrastructure and relationships with other major stealers, and its stolen data feeds credential markets and account takeover operations.

First seen
May 2022
Last seen
October 2026
VidarStealer
Alert Name
ByteCode-MSIL.Spyware.Vidar
ByteCode-MSIL.Trojan.Vidar
DOS.Trojan.Vidar
Dump:Generic.Vidar.A.C16DC869
Gen:Variant.Vidar.1019
Gen:Variant.Vidar.1035
Gen:Variant.Vidar.1067
Gen:Variant.Vidar.1083
Gen:Variant.Vidar.1225
Gen:Variant.Vidar.13