Scworld Vidar Infostealer Adopts Fileless Techniques Using JPEG and TXT Payloads
Article Content
- •Vidar infostealer now uses JPEG and TXT files for stealthy, fileless attacks.
- •The malware targets credentials and cryptocurrency wallets from over 200 browser extensions.
- •Social engineering tactics are employed to lure victims into executing malicious payloads.
The Vidar infostealer has evolved into a sophisticated multi-stage attack framework that utilizes fileless techniques to evade detection. Attackers embed malicious payloads within JPEG images and TXT documents, leveraging social engineering tactics such as fake GitHub repositories and compromised WordPress sites to lure victims. Initial access is gained through VBScript and PowerShell, with the malware employing living-off-the-land binaries like WScript and RegAsm.exe for execution. The campaign targets sensitive information, including credentials and cryptocurrency wallets, exfiltrating data via Telegram and Cloudflare-fronted domains. Researchers have documented the infection chain, highlighting the use of steganography and in-memory execution to avoid traditional security measures. Security professionals are advised to monitor for suspicious activity related to these file types and to implement behavior-based detection strategies. The scope of impact includes users of over 200 browser extensions, making it a significant threat to personal and organizational security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Vidar in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques Google's Threat Intelligence Group (GTIG) is tracking three Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting individuals in academia, defense, and government across Europe and the U.S. These groups exploit legitimate authentication workflows, such as OAuth and app password phishing, to…