Fake Software Tutorials on TikTok Spread Vidar Stealer

June 11, 2026, 7:36 a.m.

Description

Threat actors are leveraging TikTok and Instagram Reels to distribute the Vidar infostealer through fake software tutorials. Two distinct campaigns use short-form videos disguised as tutorials for unlocking premium software like Spotify. The first campaign uses accounts mimicking official Windows profiles with AI-voiced clips instructing users to run PowerShell commands that download Vidar from lookalike domains. One video achieved over 100,000 views. The second campaign uses ordinary accounts posting music-backed clips that bait users in comments to receive malicious links via direct message. These campaigns exploit platform recommendation algorithms by encouraging saves and shares. Vidar is sold as a service for $300 lifetime license and harvests credentials, financial data and authentication tokens.

Date

  • Created: June 10, 2026, 4:22 p.m.
  • Published: June 10, 2026, 4:22 p.m.
  • Modified: June 11, 2026, 7:36 a.m.

Additional Informations

  • d4ug.site
  • msget.run