Vidar Stealer 2.0 fake game-cheat distribution
Malware Activity
Summary
Hide ▲
Show ▼
The Vidar Stealer 2.0 malware is being spread through fake game-cheat repositories and Reddit lures, putting players seeking cheats for major online games at risk of credential theft and data exfiltration. The loaders add Windows Defender exclusions, fetch payloads from Pastebin/GitHub, and hide a scheduled task for persistence. The stealer can harvest browser credentials, cookies, autofill data, wallets, and other local files before sending them to Telegram and Steam dead-drop infrastructure.
Related Happenings
Vidar Stealer ClickFix campaign targeting multiple sectors
Campaign
First: 08.05.2026 14:00
Last: 08.05.2026 14:00
Sources 1
About this happening:
The **Vidar Stealer** campaign is using **ClickFix** social engineering and compromised **WordPress** sites to deliver password-stealing malware, widening risk for **infrastructur...
Vidar Stealer ClickFix campaign targeting multiple sectors
CampaignAbout this happening: The **Vidar Stealer** campaign is using **ClickFix** social engineering and compromised **WordPress** sites to deliver password-stealing malware, widening risk for **infrastructur...
ACSC ClickFix mitigation guidance for Vidar Stealer
Advisory/Mitigation
First: 07.05.2026 21:00
Last: 07.05.2026 21:00
Sources 1
About this happening:
The **ACSC** issued mitigation guidance for an **ongoing ClickFix campaign** that is pushing **Vidar Stealer** through **malicious PowerShell commands**, increasing credential-the...
ACSC ClickFix mitigation guidance for Vidar Stealer
Advisory/MitigationAbout this happening: The **ACSC** issued mitigation guidance for an **ongoing ClickFix campaign** that is pushing **Vidar Stealer** through **malicious PowerShell commands**, increasing credential-the...
Vidar infostealer market rise and distribution expansion
Malware Activity
First: 28.04.2026 22:07
Last: 28.04.2026 22:07
Sources 1
About this happening:
**Vidar** remains a long-running **infostealer** threat, and **Aryaka** reported a fresh campaign in **recent weeks** that adds **new obfuscation techniques** and stronger **steal...
Vidar infostealer market rise and distribution expansion
Malware ActivityAbout this happening: **Vidar** remains a long-running **infostealer** threat, and **Aryaka** reported a fresh campaign in **recent weeks** that adds **new obfuscation techniques** and stronger **steal...
Claude Code leak GitHub Vidar lure campaign
Campaign
First: 02.04.2026 23:30
Last: 02.04.2026 23:30
Sources 1
About this happening:
A **malicious GitHub repository campaign** is abusing the **Claude Code leak** to deliver **Vidar** to users searching for leaked code. The lure uses a **fake leak**, **search-eng...
Claude Code leak GitHub Vidar lure campaign
CampaignAbout this happening: A **malicious GitHub repository campaign** is abusing the **Claude Code leak** to deliver **Vidar** to users searching for leaked code. The lure uses a **fake leak**, **search-eng...
Malicious Steam games distributing infostealers and cryptodrainers
Malware Activity
First: 13.03.2026 22:52
Last: 13.03.2026 22:52
Sources 1
About this happening:
Multiple **Steam games** were used to deliver **information-stealing malware**, putting players' **credentials** and **cryptocurrency wallets** at risk. The abuse spanned **eight...
Malicious Steam games distributing infostealers and cryptodrainers
Malware ActivityAbout this happening: Multiple **Steam games** were used to deliver **information-stealing malware**, putting players' **credentials** and **cryptocurrency wallets** at risk. The abuse spanned **eight...
Timeline
-
18.03.2026 13:15 2 articles · 2mo ago
Acronis TRU identifies fake game-cheat lures distributing Vidar 2.0
Initial DisclosureAcronis TRU identified hundreds of GitHub repositories and Reddit posts posing as free game cheats that deliver Vidar 2.0, with lures aimed at users seeking cheats for major online games and Counter-Strike 2. The researchers said the malicious repositories could number in the thousands and described disguised loaders such as TempSpoofer.exe, Monotone.exe, CFXBypass.exe, and EzFrags_Private.zip.
Show sources
- Vidar Stealer 2.0 Exploits GitHub, Reddit to Deliver Malware via Fake Game Cheats — www.infosecurity-magazine.com — 18.03.2026 13:15
- Vidar Stealer 2.0 Exploits GitHub, Reddit to Deliver Malware via Fake Game Cheats — www.infosecurity-magazine.com — 18.03.2026 13:15