Friday, August 21, 2026

Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

Threat actors are exploiting interest in generative AI software to distribute the Vidar information stealer through a fake Google Gemini installer hosted via Google Colab.

Darktrace investigated the July 2026 intrusion in an EMEA customer environment, where a user downloaded and executed a malicious file named Download_Google_Gemini_For_Windows.exe

The campaign did not rely on a conventional phishing attachment. Instead, it exploited a software acquisition workflow that users increasingly regard as routine: searching online for an AI tool, finding a seemingly credible result, and downloading what appears to be a legitimate installer.

This approach turns trust in both Google branding and cloud-hosted developer services into an initial-access vector.

Darktrace’s investigation found that a search result associated with the suspicious filename pointed to a Google Colab page.

The Colab page reportedly displayed a download prompt that redirected victims to micronsoftwares[.]com, a secondary domain masquerading as a “Windows Software Hub.”

That site offered the purported Gemini installer. Although investigators could not conclusively reconstruct the download chain from HTTP or file-download telemetry.

The Google Colab page containing a download prompt for the fake Google Gemini installer (Source : Darktrace).
The Google Colab page containing a download prompt for the fake Google Gemini installer (Source : Darktrace).

SSL sessions to Google Colab immediately preceded execution of the suspicious binary, strongly suggesting interaction with the malicious resource and its redirect chain.

At the time of Darktrace’s review on July 15, the Colab page remained active and offered a ZIP archive containing the executable.

Fake Google Gemini Installer

Darktrace investigation found that, Google Colab is a legitimate browser-based Jupyter notebook service widely used by developers, researchers, and data scientists, making it a persuasive staging point for a malware lure.

The secondary website posing as a "Windows Software Hub" download page, which likely hosted the fake Gemini installer (Source : Darktrace).
 The secondary website posing as a “Windows Software Hub” download page, which likely hosted the fake Gemini installer (Source : Darktrace).

The archive also included a README that instructed users to run the binary with administrator privileges and add it to antivirus exclusions classic social-engineering steps intended to weaken endpoint protections and maximize the chance of successful execution.

Darktrace identified the payload as a newer Go-compiled Vidar variant communicating with Telegram-based infrastructure. Researchers associated dtm[.]kijangturbo88[.]top with command-and-control activity tied to the operation.darktrace+1

Following execution, the process connected to 91.98.98[.]86 over TCP/443. Analysis of related SSL telemetry also identified 91.98.111[.]49 as infrastructure associated with the incident.

Darktrace later received Microsoft Defender for Endpoint alerts indicating browser-credential theft and collection of other sensitive data from the infected device.

Automated containment actions implemented by Darktrace's Autonomous Response following the detection of activity associated with the fake Gemini installer  (Source : Darktrace).
Automated containment actions implemented by Darktrace’s Autonomous Response following the detection of activity associated with the fake Gemini installer (Source : Darktrace).

Vidar is an established information stealer commonly used to harvest saved browser passwords, session cookies, autofill data, cryptocurrency-wallet artifacts, and other locally stored credentials.

Its use in this operation is technically unsurprising; the notable element is the delivery chain, which repackages mature commodity malware behind a timely AI-themed lure.

Darktrace detected the compromise through behavioral signals rather than relying solely on the reputation of the downloaded file or hosting platform.

The security firm identified suspicious process execution from the user’s Downloads folder, anomalous encrypted outbound traffic, and indicators consistent with credential collection.

Its Autonomous Response capability then blocked communication with malicious infrastructure, including 91.98.98[.]86, and quarantined the compromised endpoint.

The response illustrates why behavioral analytics remain essential when adversaries host lures on reputable services and rely on users to defeat security controls manually.

The incident reflects a broader shift in malware distribution: attackers are following enterprise adoption trends and packaging threats as AI assistants, coding tools, browser extensions, and productivity applications.

A trusted cloud platform combined with a recognizable AI brand can reduce victim suspicion far more effectively than an unfamiliar phishing domain.

Organizations should restrict software installation to approved sources, prevent users from adding antivirus exclusions, monitor execution from Downloads and temporary directories, and hunt for the listed infrastructure and suspicious Gemini-branded installers.

Most importantly, users should obtain Gemini and other AI products only through official vendor channels not through search-result download pages, cloud notebooks, or third-party “software hubs.”

IOCs

IoCTypeDescription
Download_Google_Gemini_For_Windows.exeFileFake Gemini-themed installer observed during the investigation.
GoogleAppInstaller.exeFileRelated executable identified through endpoint telemetry.
91.98.98[.]86IP AddressExternal destination contacted by the malicious executable.
91.98.111[.]49IP AddressRelated infrastructure identified through SSL certificate pivoting.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Windows Defender Driver Abuse Enables Kernel-Level EDR and Antivirus Bypass

Security researcher Jiří Vinopal has published a detailed analysis...

Microsoft Entra ID RCE Flaw Lets Unauthorized Attackers Execute Code Remotely

Microsoft has disclosed a critical remote code execution vulnerability...

SilkParasite Uses Google Drive as C2 to Hide RAT Traffic Inside Trusted Cloud Services

SilkParasite, a long-running cyberespionage operation targeting government bodies across...

MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data

MacSync Stealer is expanding its macOS-focused theft operation through...

New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts

Security researchers Tom Stacey from PortSwigger and Tobia Righi...

New Zombie Card Attack Lets Expired Visa Cards Make Contactless Payments

Security researchers have demonstrated a “Zombie Card” attack that...

Related Articles

Recent News