INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Vidar Infostealer Hammers SMBs via Malvertising Campaign
| 2026-07-08 16:45 DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A malvertising campaign targeting consumers and small to midsize businesses (SMBs) globally, launched in April 2026, has been uncovered by researchers from Palo Alto Networks' Unit 42. The attackers are believed to be an experienced affiliate of the Vidar malware-as-a-service operation, primarily operating in the US and Europe. Approximately 43 samples of the malicious files have been analyzed, with 27 unique build UUIDs observed across them. When a victim executes the downloaded file, a Go-based loader launches, bypassing Antimalware Scan Interface (AMSI) before deploying payloads that deliver the Vidar infostealer and cryptomining malware. The current status is unclear as no further information on the campaign's impact or duration has been reported by Unit 42 researchers Bharath Nannaka and Pranay Kumar Chhaparwal.
Technical Mitigations AI-generated
• Use a browser extension or plugin that detects and blocks malicious certificates, such as those used by the JustWatch fabricated certificate.
• Implement an in-memory Antimalware Scan Interface (AMSI) bypass detection technique to prevent malware from evading sandbox analysis.
• Regularly monitor system logs for suspicious activity related to Windows Registry Run keys and scheduled tasks, which can be exploited by the Vidar loader to establish persistence.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
po•••••.supportxmr
Mp•••••.dll
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Tactical Metrics
Intelligence Sources
Dark Reading
2026-07-08