INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Deploys Vidar Infostealer and Monero Crypto Miner
| 2026-07-08 11:00 DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A new malicious campaign was detected in April 2026, targeting consumers and small businesses worldwide to steal sensitive cryptocurrency data and mine Monero. Attackers lured victims via malvertising to download files impersonating cracked versions of copyright-protected software, including JustWatch GmbH, a legitimate German streaming guide service, and one resembling BleacherReport.com. The campaign was first detected by Unit 42 in April 2026, with the malicious files delivered via password-protected archives containing the Vidar infostealer and XMRig cryptocurrency miner. JustWatch itself has not been compromised, according to researchers who published a report on July 7. The attackers used anti-analysis techniques such as process enumeration and AMSI bypass to evade detection by security software. Currently, the campaign is ongoing with unknown number of affected entities worldwide.
Technical Mitigations AI-generated
• Patch the AmsiScanBuffer function to prevent detection by some types of security software.
• Use a reputable anti-virus solution that can detect and block malicious files with .bin extensions in filenames.
• Monitor for suspicious activity related to Telegram operator notifications containing the tag 'X3D MINER'.
• Implement email gateway scanning to detect password-protected archives with malicious content.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Intelligence Sources
Infosecurity-Magazine
2026-07-08
New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
Infosecurity-Magazine