Vidar Stealer 2.0 Spreads via Fake Game Cheats Shared on GitHub and Reddit
## Vidar Stealer 2.0: New Campaigns Targeting Gamers
Vidar Stealer 2.0: New Campaigns Targeting Gamers
Recent large-scale campaigns have been observed utilizing platforms such as GitHub and Reddit to distribute Vidar Stealer 2.0 through counterfeit "free game cheats." These campaigns specifically target players of popular online games. The shift in criminal demand towards Vidar follows the takedown of other infostealers, highlighting gaming communities as an attractive target.
Attackers are employing tactics that involve hiding download links within images and redirecting victims through third-party sites, complicating efforts for automated detection and takedown. Initial engagement often occurs through posts on subreddits or Discord communities centered around game cheats, offering supposed free cheats for games like CS2.
Gamers seeking free cheats are particularly vulnerable as they often bypass official channels, anticipate security alerts, and are less likely to report any compromise. Vidar 2.0, once executed, collects a wide array of data including browser credentials, cookies, Azure tokens, cryptocurrency wallets, and more. This data is then exfiltrated to attacker-controlled infrastructure, with compromised gaming accounts holding potential real-world value.
Minors and young adults are disproportionately affected due to potential lack of security awareness. Some variants involve victims downloading fake tools, which are actually PowerShell loaders compiled as .NET binaries. Vidar 2.0 samples employ advanced techniques for data theft and concealment, utilizing platforms like Telegram and Steam for command-and-control (C2) communication.
The shift in criminal demand towards Vidar follows the takedown of other infostealers, highlighting gaming communities as an attractive target.
Vidar 2.0 marks a significant evolution from its predecessors, featuring a complete rewrite from C++ to C and incorporating multithreaded execution. It utilizes pervasive control-flow obfuscation, debugger checks, and timing-based anti-analysis to avoid detection. The stealer's capabilities include custom browser decryption logic, extensive file-grabbing, and targeted data theft across various user directories and platforms.
With an automated morpher altering its code structure between builds, Vidar 2.0 aims to evade static detection. Its integration of dead-drop C2 hiding on platforms like Telegram and Steam enables rapid and discreet data exfiltration.
The infostealer ecosystem has been reshaped by disruptions to services like Lumma and Rhadamanthys, with Vidar becoming an attractive alternative due to its cost-effectiveness and robust feature set. This has led to an increase in Vidar-based campaigns across social media and gaming platforms.
Security teams are advised to treat gaming-related traffic and unauthorized executable downloads as high-risk, implementing strict application-control policies and user education to address the threat posed by "free cheats."
Based on reporting by GBHackers.
