Vidar Stealer 2.0 Spreads via Fake Game Cheats on GitHub and Reddit

Vidar Stealer 2.0 Spreads via Fake Game Cheats on GitHub and Reddit

First seen 18 Mar 2026, 12:12 UTC Infosecurity-MagazineCybersecuritynewsScworld 87% similarity 64.5

Article Content

Browse articles
ThreatCluster

Acronis Threat Research Unit reported that the Vidar Stealer 2.0 is being distributed through hundreds of fake game cheat repositories on GitHub and targeted posts on Reddit. The malware masquerades as free cheating software for popular online games, luring gamers into downloading it. The campaign has been identified to target virtually every major online game title, with the number of malicious repositories potentially reaching into the thousands. Attackers promote these cheats in Discord communities dedicated to gaming, exploiting the willingness of users to bypass security warnings. The malware, once installed, can extract sensitive information such as browser credentials and cookies. The first-stage payloads are disguised as game cheats and are executed through a multi-stage infection process. The malicious software connects to known command-and-control infrastructure, indicating a coordinated effort by the same threat actors. The report emphasizes the novelty of the delivery method for Vidar 2.0, marking a significant evolution in its distribution tactics.

Key Points: • Vidar Stealer 2.0 spreads through fake game cheats on GitHub and Reddit. • The malware targets major online games, with potentially thousands of malicious repositories. • Gamers are tricked into downloading the malware, which steals sensitive information.

ThreatCluster AI

Timeline

2026-03-17
Acronis TRU publishes report on Vidar Stealer 2.0 distribution
2026-03-18
Articles published detailing the ongoing malware campaign

Community

Browse all →