Vidar Stealer Bypassing Browser Security Via Direct Memory Injection to Steal Login Credentials
On Fri, Oct 6, 2025, the Vidar Stealer malware was updated to version 2.0, featuring significant architectural changes designed to bypass Chrome's security measures through direct memory injection. Developed by "Loadbaks," this version has been rewritten…
On Fri, Oct 6, 2025, the Vidar Stealer malware was updated to version 2.0, featuring significant architectural changes designed to bypass Chrome's security measures through direct memory injection. Developed by "Loadbaks," this version has been rewritten from C++ to C, enhancing its multithreaded architecture for improved data exfiltration and evasion capabilities.
Vidar 2.0 is priced at $300 for lifetime access and targets credentials from browsers, cryptocurrency wallets, cloud services, gaming platforms, and communication applications such as Discord and Telegram. This update comes at a time when the activity of similar malware, Lumma Stealer, has declined, positioning Vidar as a prominent option in the market.
According to Trend Micro analysts, Vidar 2.0 introduces the following updates:
Complete rewrite in C for enhanced stability and performance. Multithreaded architecture that scales dynamically based on system specifications. Advanced browser credential extraction features. Automatic polymorphic builder for unique binary signatures.
This update comes at a time when the activity of similar malware, Lumma Stealer, has declined, positioning Vidar as a prominent option in the market.
Vidar 2.0 exploits Chrome’s AppBound encryption protections through advanced memory injection techniques. This allows the malware to bypass Chrome's security measures aimed at preventing unauthorized credential extraction. The malware employs a two-step approach:
Attempting traditional methods such as browser profile enumeration and DPAPI decryption. Using advanced techniques to inject malicious code directly into browser processes if traditional methods fail.
This dual-pronged strategy targets both standard browser storage methods and Chrome's latest protections, facilitating comprehensive credential theft across multiple platforms including Chrome, Firefox, Edge, and other Chromium-based browsers.
The injected payload operates within browser memory, extracting encryption keys directly from active processes, thus avoiding disk artifacts that could be detected through forensic analysis or security software. This method effectively circumvents Chrome’s encryption as it accesses keys that are already decrypted and in use by the browser.
For more updates, please follow our channels on Google News , LinkedIn , and X .
Based on reporting by Cyber Security News.
