Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical D-Link Router Flaw CVE-2024-39148 Lets Attackers Remotely Execute Code
September 22, 2026
Vidar Malware Updates Obfuscation With Every Build to Evade Detection
September 22, 2026
Critical Microsoft AD Vulnerability Lets Attackers Forge Golden Tickets
September 22, 2026
Home/Threats/Vidar Malware Updates Obfuscation With Every Build to Evade Detection
Threats

Vidar Malware Updates Obfuscation With Every Build to Evade Detection

Key Takeaways Vidar, an information-stealing malware, has significantly upgraded its obfuscation techniques to evade detection. The malware now employs a custom virtual machine and unique stream...

Emy Elsamnoudy
Emy Elsamnoudy
September 22, 2026 4 Min Read
2 0

Key Takeaways

  • Vidar, an information-stealing malware, has significantly upgraded its obfuscation techniques to evade detection.
  • The malware now employs a custom virtual machine and unique stream ciphers that change with every new build.
  • This advanced obfuscation makes traditional file-based signatures and automated analysis less effective.
  • Vidar continues to target sensitive data such as saved passwords, browser cookies, and cryptocurrency wallet files.
  • Detection strategies must now focus more on behavioral analysis, process activity, and network anomalies rather than static code patterns.

Vidar Malware Rewrites Its Obfuscation

Vidar, a persistent information stealer active since 2018, has consistently evolved its methods to pilfer critical user data, including stored passwords, browser cookies, digital wallet files, and system configurations. Recent analysis reveals a significant upgrade in the malware’s stealth capabilities, making it substantially more challenging for cybersecurity defenses to identify before execution.

Table Of Content

  • Key Takeaways
  • Vidar Malware Rewrites Its Obfuscation
  • Advanced String Hiding
  • Custom Ciphers Raise the Cost of Analysis
  • What You Should Do
  • Indicators of Compromise (IoCs):-

Throughout its operational history, Vidar has adapted through numerous code rewrites. Current campaigns frequently leverage social engineering tactics, distributing the malware via deceptive software installers and downloads promoted on video platforms. Other observed distribution vectors include malicious online repositories and fraudulent game-cheat offerings.

The consequences of a Vidar infection are severe. Compromised browser data can grant attackers unauthorized access to email accounts, corporate applications, financial services, and cryptocurrency holdings. As Zscaler said in a report, even a single infected corporate device can expose reusable credentials and active sessions, providing a gateway for broader system compromise. Researchers at Zscaler meticulously tracked Vidar’s evolution from May through early September 2026, pinpointing its latest obfuscation advancements.

Zscaler’s findings indicate a progression in Vidar’s string-hiding techniques. Initially employing basic XOR encryption, the malware transitioned to modified ChaCha20 routines, and has now adopted a sophisticated custom virtual machine and unique stream ccipher, both of which are dynamically altered with each new build. This PDF report highlights the malware’s sophisticated and adaptive nature.

Advanced String Hiding

The core of Vidar’s new evasion strategy lies in its dynamic string-hiding methods. Strings, which are human-readable code segments revealing commands, configuration details, error messages, and intended actions, are now obscured in a unique way for each malware variant. This dynamic obfuscation renders traditional file-based signatures and automated analysis tools significantly less effective.

In versions 2.x and 3.x of Vidar, the malware executes a compact virtual machine via a bytecode interpreter. This interpreter processes a sequence of instructions, manipulating a single-byte working value and only revealing decoded text at specific junctures. The design, while seemingly straightforward, is intentionally inconsistent across different builds, contributing to its evasiveness.

Researchers discovered a sparse 256-entry table containing 14 distinct instruction handlers. These handlers perform standard operations such as addition, subtraction, rotation, XOR, multiplication, and substitution. Crucially, the opcodes, constants, and lookup tables are randomized with each build. Furthermore, a four-byte XOR key, which seeds the interpreter, also changes dynamically. This contrasts sharply with static packers, which, once unpacked, can be recognized repeatedly, as Vidar continuously alters the minor details that detection rules typically rely upon. This adaptability is also evident in reports detailing Vidar’s ability to bypass security controls and harvest credentials.

The virtual machine can either directly expose a string or retrieve a key and nonce to decrypt a secondary data block. This multi-layered approach means security analysts must first reverse-engineer the constantly changing interpreter before they can access some of the malware’s critical textual components, significantly increasing the complexity and time required for analysis.

Custom Ciphers Raise the Cost of Analysis

Vidar further enhances its obfuscation by coupling the virtual machine with custom stream ciphers. Earlier versions (2.0 and 2.1) utilized a modified ChaCha-based design, while version 2.2 and subsequent releases transitioned to an add-rotate-XOR methodology. Although the interface remains familiar, the underlying arithmetic and constant values are unique to each sample.

This evolving pattern substantially increases the effort needed to analyze new Vidar samples, delaying the creation of detection rules based on static strings. While these methods do not render the malware completely undetectable, they compel defenders to shift their focus towards behavioral analysis, monitoring process activity, detecting unusual network connections, and identifying suspicious access to browser data, rather than relying on fixed code patterns.

The ongoing changes coincide with Vidar’s continued prevalence in social engineering campaigns. Examples include fake Gemini installer campaigns, which trick users into downloading the malware and subsequently stealing browser passwords, and fraudulent YouTube software downloads used to target employees. These per-build obfuscation techniques are designed to specifically frustrate static and automated analysis systems.

This intelligence underscores the critical need for organizations to maintain up-to-date endpoint monitoring, proactively investigate any unusual browser data collection, and rigorously restrict unverified software downloads before users have a chance to execute them. The broader implication is that effective malware detection must prioritize understanding a program’s actions over merely analyzing its static code, especially as Vidar’s credential theft operations continue to impact Windows users.

What You Should Do

  • Implement robust endpoint detection and response (EDR) solutions capable of behavioral analysis.
  • Educate users on identifying social engineering tactics, such as fake software installers and deceptive downloads.
  • Enforce strict policies regarding software downloads from unverified sources.
  • Regularly monitor network traffic for unusual connections and data exfiltration attempts.
  • Upon suspected infection, immediately reset all exposed credentials and revoke active sessions, especially for accounts with administrative or business access.
  • Conduct regular security audits of browser profiles and stored credentials.

Indicators of Compromise (IoCs):-

Further technical details and indicators of compromise are available in this <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/89550b72-de4e-4fee-b6df-3c99001d3841/Vidar-Malware-Rewrites-Its-Obfuscation-With-Every-Build-to-Make-Detection-Harder.pdf?AWSAccessKeyId=ASIA2F3EMEYEW5GJCOO7&Signature=lar%2FbLKiMMWqgn064e8%2B01ypTRk%3D&x-amz-security-token=IQoJb3JpZ2luX2VjENn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIQCOgi9nIQa0wTcQRBXzx1bZYOYuyZ%2Bb5vRxxHOiGdbhbwIfNh2D8jbGQMpWMCXRuIPEHsxSnhGJKUNFXt%2FMfwpHOir8BAih%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMnEvSjCD6y5iAO%2BUHKtAEtCBHhoGDBJyxKT%2BNRCFwiFACRvvnm2H9fwuGJRUAWq4s433tqxKfTe3OqI%2Fn0ebQ9Bc9t1pdl%2FIFXhFsDLC4ymNPyQlJGElDroLcPMa%2F3LGhgqTMmV1oZOMyjsaFUcPOSEwqP4JfeWWkWq%2FCNL4Hp3l9tAfb%2F98DeUHvdIRHYSuEUJf3hmpG%2BHx2V5HTE2SB3X8L0hGr2r9DPofxzAHkvC0r3w4%2B1sZUJwqbwPMSTdIH1BnbirT6pfUxgMqT5FsFBeyzyjHbjEdbUDYIKoFb8ZABZ%2BrdyokS0IPeAiKJpMPANkjqxxm5wYRmjZlN3vaAtLYrGi0J61GOfHTm4ZZX6hycJhiEPwTjUctJiaQTvef%2B5AT99Xnqy1SfQ8uHEjmYt%2BM5T2cYdKje1FiLWK7mfllrvMdi1mO7I%2Fb3fVD3xriR5Q3KHbm8jXROGeUlr7ynjVdxYx6e280bRsWcd9otYPeeKFSTUuABOr%2FugroQeh7ZP9t%2FB%2BECCuCmXwXLOumFgCAWy%2B0Oe3zkPQvflBB4%2BXMwr6c5fl

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

MalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Microsoft AD Vulnerability Lets Attackers Forge Golden Tickets

Next Post

Critical D-Link Router Flaw CVE-2024-39148 Lets Attackers Remotely Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best Customer Identity and Access Management (CIAM) Solutions 2024
September 22, 2026
Top 10 Identity Threat Detection and Response (ITDR) Tools for 2026
September 22, 2026
CISA Warns of Actively Exploited Critical Zyxel GS1900 Switch Flaw
September 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us