Cybersecuritynews Vidar Stealer 2.0 Spreads via Fake Game Cheats on GitHub and Reddit
Article Content
- •Vidar Stealer 2.0 spreads through fake game cheats on GitHub and Reddit.
- •The malware targets major online games, with potentially thousands of malicious repositories.
- •Gamers are tricked into downloading the malware, which steals sensitive information.
Acronis Threat Research Unit reported that the Vidar Stealer 2.0 is being distributed through hundreds of fake game cheat repositories on GitHub and targeted posts on Reddit. The malware masquerades as free cheating software for popular online games, luring gamers into downloading it. The campaign has been identified to target virtually every major online game title, with the number of malicious repositories potentially reaching into the thousands. Attackers promote these cheats in Discord communities dedicated to gaming, exploiting the willingness of users to bypass security warnings. The malware, once installed, can extract sensitive information such as browser credentials and cookies. The first-stage payloads are disguised as game cheats and are executed through a multi-stage infection process. The malicious software connects to known command-and-control infrastructure, indicating a coordinated effort by the same threat actors. The report emphasizes the novelty of the delivery method for Vidar 2.0, marking a significant evolution in its distribution tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Vidar 2.0 and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…