Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

db2a872f712fbdb1e347d06e29a9ed8278d86710ffc14ff04422be76e47124f4

TLP:CLEAR
Active

SHA-256 Hash

Description

A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:07
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of db2a872f712fbdb1e347d06e29a9ed8278d86710ffc14ff04422be76e47124f4

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.