Fake Software Tutorials on TikTok Spread Vidar Stealer
June 11, 2026, 7:36 a.m.
Description
Threat actors are leveraging TikTok and Instagram Reels to distribute the Vidar infostealer through fake software tutorials. Two distinct campaigns use short-form videos disguised as tutorials for unlocking premium software like Spotify. The first campaign uses accounts mimicking official Windows profiles with AI-voiced clips instructing users to run PowerShell commands that download Vidar from lookalike domains. One video achieved over 100,000 views. The second campaign uses ordinary accounts posting music-backed clips that bait users in comments to receive malicious links via direct message. These campaigns exploit platform recommendation algorithms by encouraging saves and shares. Vidar is sold as a service for $300 lifetime license and harvests credentials, financial data and authentication tokens.
Tags
Date
- Created: June 10, 2026, 4:22 p.m.
- Published: June 10, 2026, 4:22 p.m.
- Modified: June 11, 2026, 7:36 a.m.
Additional Informations
- d4ug.site
- msget.run