Skip to content
Vidar Infostealer Adopts Fileless Techniques Using JPEG and TXT Payloads

Vidar Infostealer Adopts Fileless Techniques Using JPEG and TXT Payloads

First seen 28 Apr 2026, 23:13 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 29, 2026 at 23:08 UTC
  • Vidar infostealer now uses JPEG and TXT files for stealthy, fileless attacks.
  • The malware targets credentials and cryptocurrency wallets from over 200 browser extensions.
  • Social engineering tactics are employed to lure victims into executing malicious payloads.

The Vidar infostealer has evolved into a sophisticated multi-stage attack framework that utilizes fileless techniques to evade detection. Attackers embed malicious payloads within JPEG images and TXT documents, leveraging social engineering tactics such as fake GitHub repositories and compromised WordPress sites to lure victims. Initial access is gained through VBScript and PowerShell, with the malware employing living-off-the-land binaries like WScript and RegAsm.exe for execution. The campaign targets sensitive information, including credentials and cryptocurrency wallets, exfiltrating data via Telegram and Cloudflare-fronted domains. Researchers have documented the infection chain, highlighting the use of steganography and in-memory execution to avoid traditional security measures. Security professionals are advised to monitor for suspicious activity related to these file types and to implement behavior-based detection strategies. The scope of impact includes users of over 200 browser extensions, making it a significant threat to personal and organizational security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 134d ago How this analysis works

Timeline

2026-04-28
Vidar's new fileless attack techniques reported by multiple sources.
2026-04-28
Research reveals the use of steganography in malware payloads.
2026-04-28
Security recommendations issued for detecting Vidar's infection chain.

More articles in this cluster (9)

Following this threat?

Track Vidar in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed