Hackers are tricking users with fake Windows 11 installers loaded with Vidar info stealer spreading through newly registered phishing domains.
The cybersecurity analysts at Zscale security firm have detected that the malicious ISO files were included on the spoofed websites to enable the downloading and installation of the Vidar info-stealer malware on the target computers.
Throat-controlling social media channels, such as Telegram and Mastodon, are used to deploy the C2 configuration of Vidar malware.
On 20 April, some of the fake domain names have been registered and here they are mentioned below:-
In addition to attacks against YouTubers, Vidar malware has been used previously by the threat actors to swindle VPN users before.
Vidar malware is an infamous info stealer that can steal information from users and spy on what they do. While malware such as Vidar is primarily designed for the purpose of stealing sensitive information from its victims.
Fallout exploit kits are usually the source of distribution of Vidar. Here below we have mentioned the types of data stolen by Vidar:-
Apart from fake Windows 11 installers, the threat actors behind Vidar also spreading this malware through malicious variants of legitimate software like:-
In order to avoid detection by security solutions, the ISO that contains the executable is unusually large in size (over 300MB).
Here, Avast’s expired certificate is used by the hackers to sign the file, and it is likely that the certificate was stolen following the company’s October 2019 security breach.
To steal essential and sensitive data from the compromised systems, Vidar establishes a connection to a C2 server, and then it requests legitimate DLL files from the C2 server.
Here below we have mentioned the DLL files that are requested:-
In addition to this abuse, the threat actor has also abused Mastodon and Telegram to store the C2 IP address in the description fields of vulnerable communities and accounts.
Here below we have mentioned a few recommendations offered by the security experts:-
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS devices.…
White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch Experts…
Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan exploits…
The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on organizations…
Google has updated its Chrome browser, addressing critical vulnerabilities that posed potential risks to millions…
WrnRAT is a new malware attack that cybercriminals have deployed by using popular gambling games…