Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Vidar v1.5 in Go: same family, new language, heavy sandbox checks

2995ffb73342453b258926ec865c724e3567eee1bb8eb35d61796ee0c4f25105

TLP:CLEAR
Active

SHA-256 Hash

Description

Vidar is a name most infostealer trackers know well -- an Arkei descendant that has been snatching browser credentials and crypto wallets since 2018. It usually ships as a .NET binary or a C++ PE. The v1.5 sample we pulled from Triage on May 13, 2026 is neither. It is a 7 MB Go 1.25.4 native PE with a twelve-category sandbox scoring system, dead-drop C2 via Telegram and Steam profile pages, and enough crypto primitives to make a librarian blush.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Vidar v1.5 in Go: same family, new language, heavy sandbox checks
Pattern Type
STIX
Confidence
75%
Valid From
May 21, 2026 03:05
Total Sightings
0
Added
May 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 2995ffb73342453b258926ec865c724e3567eee1bb8eb35d61796ee0c4f25105

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.