Vidar Malware Updates Obfuscation With Every Build to Evade Detection
Key Takeaways Vidar, an information-stealing malware, has significantly upgraded its obfuscation techniques to evade detection. The malware now employs a custom virtual machine and unique stream...
Key Takeaways
- Vidar, an information-stealing malware, has significantly upgraded its obfuscation techniques to evade detection.
- The malware now employs a custom virtual machine and unique stream ciphers that change with every new build.
- This advanced obfuscation makes traditional file-based signatures and automated analysis less effective.
- Vidar continues to target sensitive data such as saved passwords, browser cookies, and cryptocurrency wallet files.
- Detection strategies must now focus more on behavioral analysis, process activity, and network anomalies rather than static code patterns.
Vidar Malware Rewrites Its Obfuscation
Vidar, a persistent information stealer active since 2018, has consistently evolved its methods to pilfer critical user data, including stored passwords, browser cookies, digital wallet files, and system configurations. Recent analysis reveals a significant upgrade in the malware’s stealth capabilities, making it substantially more challenging for cybersecurity defenses to identify before execution.
Table Of Content
Throughout its operational history, Vidar has adapted through numerous code rewrites. Current campaigns frequently leverage social engineering tactics, distributing the malware via deceptive software installers and downloads promoted on video platforms. Other observed distribution vectors include malicious online repositories and fraudulent game-cheat offerings.
The consequences of a Vidar infection are severe. Compromised browser data can grant attackers unauthorized access to email accounts, corporate applications, financial services, and cryptocurrency holdings. As Zscaler said in a report, even a single infected corporate device can expose reusable credentials and active sessions, providing a gateway for broader system compromise. Researchers at Zscaler meticulously tracked Vidar’s evolution from May through early September 2026, pinpointing its latest obfuscation advancements.
Zscaler’s findings indicate a progression in Vidar’s string-hiding techniques. Initially employing basic XOR encryption, the malware transitioned to modified ChaCha20 routines, and has now adopted a sophisticated custom virtual machine and unique stream ccipher, both of which are dynamically altered with each new build. This PDF report highlights the malware’s sophisticated and adaptive nature.
Advanced String Hiding
The core of Vidar’s new evasion strategy lies in its dynamic string-hiding methods. Strings, which are human-readable code segments revealing commands, configuration details, error messages, and intended actions, are now obscured in a unique way for each malware variant. This dynamic obfuscation renders traditional file-based signatures and automated analysis tools significantly less effective.
In versions 2.x and 3.x of Vidar, the malware executes a compact virtual machine via a bytecode interpreter. This interpreter processes a sequence of instructions, manipulating a single-byte working value and only revealing decoded text at specific junctures. The design, while seemingly straightforward, is intentionally inconsistent across different builds, contributing to its evasiveness.
Researchers discovered a sparse 256-entry table containing 14 distinct instruction handlers. These handlers perform standard operations such as addition, subtraction, rotation, XOR, multiplication, and substitution. Crucially, the opcodes, constants, and lookup tables are randomized with each build. Furthermore, a four-byte XOR key, which seeds the interpreter, also changes dynamically. This contrasts sharply with static packers, which, once unpacked, can be recognized repeatedly, as Vidar continuously alters the minor details that detection rules typically rely upon. This adaptability is also evident in reports detailing Vidar’s ability to bypass security controls and harvest credentials.
The virtual machine can either directly expose a string or retrieve a key and nonce to decrypt a secondary data block. This multi-layered approach means security analysts must first reverse-engineer the constantly changing interpreter before they can access some of the malware’s critical textual components, significantly increasing the complexity and time required for analysis.
Custom Ciphers Raise the Cost of Analysis
Vidar further enhances its obfuscation by coupling the virtual machine with custom stream ciphers. Earlier versions (2.0 and 2.1) utilized a modified ChaCha-based design, while version 2.2 and subsequent releases transitioned to an add-rotate-XOR methodology. Although the interface remains familiar, the underlying arithmetic and constant values are unique to each sample.
This evolving pattern substantially increases the effort needed to analyze new Vidar samples, delaying the creation of detection rules based on static strings. While these methods do not render the malware completely undetectable, they compel defenders to shift their focus towards behavioral analysis, monitoring process activity, detecting unusual network connections, and identifying suspicious access to browser data, rather than relying on fixed code patterns.
The ongoing changes coincide with Vidar’s continued prevalence in social engineering campaigns. Examples include fake Gemini installer campaigns, which trick users into downloading the malware and subsequently stealing browser passwords, and fraudulent YouTube software downloads used to target employees. These per-build obfuscation techniques are designed to specifically frustrate static and automated analysis systems.
This intelligence underscores the critical need for organizations to maintain up-to-date endpoint monitoring, proactively investigate any unusual browser data collection, and rigorously restrict unverified software downloads before users have a chance to execute them. The broader implication is that effective malware detection must prioritize understanding a program’s actions over merely analyzing its static code, especially as Vidar’s credential theft operations continue to impact Windows users.
What You Should Do
- Implement robust endpoint detection and response (EDR) solutions capable of behavioral analysis.
- Educate users on identifying social engineering tactics, such as fake software installers and deceptive downloads.
- Enforce strict policies regarding software downloads from unverified sources.
- Regularly monitor network traffic for unusual connections and data exfiltration attempts.
- Upon suspected infection, immediately reset all exposed credentials and revoke active sessions, especially for accounts with administrative or business access.
- Conduct regular security audits of browser profiles and stored credentials.
Indicators of Compromise (IoCs):-
Further technical details and indicators of compromise are available in this <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/89550b72-de4e-4fee-b6df-3c99001d3841/Vidar-Malware-Rewrites-Its-Obfuscation-With-Every-Build-to-Make-Detection-Harder.pdf?AWSAccessKeyId=ASIA2F3EMEYEW5GJCOO7&Signature=lar%2FbLKiMMWqgn064e8%2B01ypTRk%3D&x-amz-security-token=IQoJb3JpZ2luX2VjENn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIQCOgi9nIQa0wTcQRBXzx1bZYOYuyZ%2Bb5vRxxHOiGdbhbwIfNh2D8jbGQMpWMCXRuIPEHsxSnhGJKUNFXt%2FMfwpHOir8BAih%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMnEvSjCD6y5iAO%2BUHKtAEtCBHhoGDBJyxKT%2BNRCFwiFACRvvnm2H9fwuGJRUAWq4s433tqxKfTe3OqI%2Fn0ebQ9Bc9t1pdl%2FIFXhFsDLC4ymNPyQlJGElDroLcPMa%2F3LGhgqTMmV1oZOMyjsaFUcPOSEwqP4JfeWWkWq%2FCNL4Hp3l9tAfb%2F98DeUHvdIRHYSuEUJf3hmpG%2BHx2V5HTE2SB3X8L0hGr2r9DPofxzAHkvC0r3w4%2B1sZUJwqbwPMSTdIH1BnbirT6pfUxgMqT5FsFBeyzyjHbjEdbUDYIKoFb8ZABZ%2BrdyokS0IPeAiKJpMPANkjqxxm5wYRmjZlN3vaAtLYrGi0J61GOfHTm4ZZX6hycJhiEPwTjUctJiaQTvef%2B5AT99Xnqy1SfQ8uHEjmYt%2BM5T2cYdKje1FiLWK7mfllrvMdi1mO7I%2Fb3fVD3xriR5Q3KHbm8jXROGeUlr7ynjVdxYx6e280bRsWcd9otYPeeKFSTUuABOr%2FugroQeh7ZP9t%2FB%2BECCuCmXwXLOumFgCAWy%2B0Oe3zkPQvflBB4%2BXMwr6c5fl
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.