Vidar Stealer 2.0 Spreads Through Fake Game Cheats Promoted on GitHub and Reddit
## Vidar 2.0 Malware Distribution through Game Cheat Repositories
Vidar 2.0 Malware Distribution through Game Cheat Repositories
The Vidar infostealer, updated as Vidar 2.0, is currently being disseminated through numerous fake game cheat repositories on GitHub and Reddit. This malware masquerades as free cheating software for popular online games, deceiving users into downloading a credential-stealing tool.
Targeted Games and User Vulnerabilities
Cybercriminals are systematically focusing on major online games such as Counter-Strike 2, Fortnite, Valorant, and Call of Duty. Gamers seeking free cheat tools are particularly vulnerable targets due to their expectations of security warnings and their valuable digital assets.
Vidar 2.0 is capable of stealing browser credentials, cookies, autofill data, Azure tokens, cryptocurrency wallets, FTP and SSH credentials, as well as Discord and Telegram session data. Its rapid operation allows data to be compromised before detection. Compromised gaming accounts are especially valuable due to the potential resale of in-game items and currency.
Threat actors are utilizing trusted platforms, hosting landing pages on GitHub to lend credibility to their operations. Reddit posts in gaming communities further direct users to these fake repositories. This strategic use of well-known platforms and social engineering creates a deceptive infection pipeline.
The Vidar infostealer, updated as Vidar 2.0, is currently being disseminated through numerous fake game cheat repositories on GitHub and Reddit.
Users who click on links in Reddit posts or visit fake GitHub pages are directed to sites with installation instructions. The setup mimics legitimate software installations, advising users to disable antivirus, extract password-protected archives, and execute files with administrator rights. These actions are often perceived as normal by those seeking cheat software.
The malicious file is a PowerShell script compiled into a .NET binary. Once activated, it adds a Windows Defender exclusion, retrieves payloads from GitHub, and establishes persistence through scheduled tasks with elevated privileges. The final payload connects to Telegram bots and Steam profiles to conceal its command-and-control infrastructure.
Organizations should implement endpoint protection or EDR tools to detect unusual process chains and data exfiltration. Keeping systems updated and restricting software execution to standard paths are essential measures. Users should download software exclusively from official vendor websites or verified repositories.
Based on reporting by Cyber Security News.
