Rewterz
Rewterz Threat Advisory – Linux Kernel privilege escalation
February 8, 2021
Rewterz
Rewterz Threat Advisory – Google Chrome V8 buffer overflow
February 8, 2021

Rewterz Threat Alert – Vidar Malware

Severity

High

Analysis Summary

Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials.

Impact

  • Data exfiltration
  • Information theft
  • Exposure of sensitive data 

Indicators of Compromise

MD5

  • 666d86da368cc44f2f48dbda2ff780db
  • 525fe19468cfdc24779bb5b4f8f06760

SHA-256

  • 90d062328ec6dcc6690f620a5b78333ae8dc9a4b712a05c654648577b025c0c8
  • e3985b9b0c3748551982465c2aa30607197c0e9367ef3a11af36774e36739cda
  • be71587b6f50fe19c339a875dbde3c28144c8b889b3ce6f3582d4d6e16890dd0

SHA1

  • d7fdc2631ff90b40f3689e03fe26d3a7e78dfbd7
  • 60e55d5ace6aff66cc33f77d536dc225f6c57da2

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.