Back Darkreading Vidar Infostealer Hammers SMBs via Malvertising Campaign
A financially motivated operation uses lures of cracked or pirated software to deliver a two-for-one malware combo for data theft and cryptomining.
Threat actors are targeting consumers and small to midsize businesses (SMBs) globally in a financially motivated malvertising campaign that delivers the Vidar infostealer and cryptomining malware with multifaceted delivery and evasion strategies.
Researchers from Palo Alto Networks' Unit 42 uncovered the campaign in April; it lures victims to pages for downloading files that impersonate cracked versions of copyright-protected software, according to a report published July 7. The files delivered, however, are actually password-protected archives that hide a malware loader for dropping and executing both the Vidar infostealer and the open source XMRig cryptominer. Vidar targets browser credentials, cookies, and crypto wallets, while the XMRig mines Monero cryptocurrency.
While the attack follows a typical playbook for malvertising , the campaign stands out for both its delivery mechanism and evasion strategies, which point to an experienced affiliate of the Vidar malware-as-a-service (MaaS) operation, which primarily operates in the US and Europe, according to Unit 42 threat researchers Bharath Nannaka and Pranay Kumar Chhaparwal.
"The operator behind this campaign runs a dual-monetization scheme," they wrote in the post. "Criminals sell credentials and session cookies stolen by Vidar stealer on criminal log markets, while XMRig provides passive income from hijacked victim CPU cycles."
Meanwhile, an aspect of the malware delivery mechanism — the Factory-v3 framework for MaaS building — also appears to be a side hustle for the operators, acting as "a separate upstream service used by at least two distinct stealer affiliates," the researchers wrote.
An attack begins when someone clicks on a malicious online ad for pirated or cracked software, which redirects them to attacker-controlled websites hosting the password-protected archives that masquerade as legitimate software installers.
The password protection "appears to be a deliberate choice to bypass email gateway scanning and to prevent automated sandbox detonation without the password," the researchers wrote. It also lends an air of legitimacy to the download that could fool skeptical users.
When the victim executes the downloaded file, a Go-based loader launches and performs a series of defense-evasion techniques, including an in-memory Antimalware Scan Interface (AMSI) bypass, before deploying its payloads. The loader leverages the Factory-v3 Go framework, which allows it to generate a unique binary per build, the researchers noted. "For example, we observed 27 unique build UUIDs across 43 samples, defeating hash-based detection," they wrote.
The loader also is signed with a fabricated certificate for JustWatch, a streaming TV guide, and uses an unusually large file size via padding with null bytes to evade detection by automated analysis, the researchers added.
Once executed, the loader installs Vidar , which harvests browser credentials, cookies, browsing history, autofill data, and cryptocurrency wallet files. Simultaneously, the malware also deploys XMRig, which quietly mines Monero in the background using the victim's CPU. Finally, the loader establishes persistence through Windows Registry Run keys and scheduled tasks to ensure the malware survives system reboots.
The campaign demonstrates how financially motivated threat actors are increasingly combining multiple monetization strategies in a single infection to maximize the value of each successful infection, the researchers noted. This demonstrates the continued evolution of MaaS operations toward more efficient, multistage attack chains, they said.
SMBs in particular should be especially careful to defend against attackers' evasion tactics, as they appear "specifically tuned for SMB-grade defenses," observes Denis Calderone, principal and chief technology officer of AI security solution provider Suzu Labs.
"Binaries padded to nearly 500MB silently skip past sandbox file-size limits most small organizations never adjust, the fake code-signing certificates lean on recognizable brand names to get users past trust warnings, and the AMSI bypass disables script scanning before any stealer logic even runs," he tells Dark Reading.
It's also no surprise that the campaign's monetization model is multifaceted, since the targets are smaller, meaning "extortion alone is going to be less profitable," Calderone adds.
To help defenders avoid compromise, Unit 42's report included a list of indicators of compromise (IoCs), such as code-signing info, server addresses, hashes, and file paths. Unit 42 also recommends that organizations enforce strong Microsoft Authenticode chain validation and supplement it with defensive measures such as: certificate serial blocklisting ; configuring security tooling to scan files regardless of size; and monitoring for MpClient.dll loading from nonstandard paths.
According to the report, strategies for defenders to bolster their security profile against the campaign and others like it include hunting the persistence indicators and file-drop patterns described in the report and immediately blocking outbound connections to all C2 addresses and pool.supportxmr[.]com.
Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician.
The State of Cloud Security: The Latest Challenges
The total economic impact™ of Snyk
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Governing the Agent; Identity Security in the Age of Autonomous AI
Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything
Practical Zero Trust Implementation on a Budget in the Age of Mythos
Building a Risk Based Vulnerability Management Program
Threat Hunting That Gets Big Results Despite Small Budgets
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
