Vidar Stealer: Infostealer malware discovered in Steam game
April 7, 2025, 10:36 p.m.
Description
A recent analysis uncovered a sophisticated deployment of Vidar Stealer, an infamous information-stealing malware, disguised as a legitimate Microsoft Sysinternals tool, BGInfo.exe. The malware, found with an expired Microsoft signature, was significantly larger than the original file and contained modified initialization routines. It creates virtual memory allocations to execute its malicious code, ultimately extracting and running Vidar Stealer. This variant maintains its core functionalities, including credential theft, cryptocurrency wallet targeting, session hijacking, and cloud data theft. The incident highlights the evolving tactics of cybercriminals, emphasizing the need for vigilant threat hunting and proactive security measures.
Tags
Date
- Created: April 7, 2025, 7:41 p.m.
- Published: April 7, 2025, 7:41 p.m.
- Modified: April 7, 2025, 10:36 p.m.
Indicators
- 7f59c7261ce53d72cafcba86c3a423f06922f1edb47b419b96d2944af3e7859d
Attack Patterns
- Vidar Stealer