INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Vidar Infostealer Hammers SMBs via Malvertising Campaign

| 2026-07-08 16:45 MEDIUM HIGH DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A malvertising campaign targeting consumers and small to midsize businesses (SMBs) globally, launched in April 2026, has been uncovered by researchers from Palo Alto Networks' Unit 42. The attackers are believed to be an experienced affiliate of the Vidar malware-as-a-service operation, primarily operating in the US and Europe. Approximately 43 samples of the malicious files have been analyzed, with 27 unique build UUIDs observed across them. When a victim executes the downloaded file, a Go-based loader launches, bypassing Antimalware Scan Interface (AMSI) before deploying payloads that deliver the Vidar infostealer and cryptomining malware. The current status is unclear as no further information on the campaign's impact or duration has been reported by Unit 42 researchers Bharath Nannaka and Pranay Kumar Chhaparwal.
Technical Mitigations AI-generated
• Use a browser extension or plugin that detects and blocks malicious certificates, such as those used by the JustWatch fabricated certificate. • Implement an in-memory Antimalware Scan Interface (AMSI) bypass detection technique to prevent malware from evading sandbox analysis. • Regularly monitor system logs for suspicious activity related to Windows Registry Run keys and scheduled tasks, which can be exploited by the Vidar loader to establish persistence.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

po•••••.supportxmr
Mp•••••.dll
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE cryptocurrencycryptocurrency
Incident Timeline
‎2026/07/08
Threat actors used malvertising to lure victims into downloading files impersonating cracked software, which then deployed the Vidar Infostealer malware.
data_breach 500 MB
infrastructure Windows
Tactical Metrics
Metrics
data_breach
500
Mb
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources