[FRIAM] Vidar Stealer 2.0
glen
gepropella at gmail.com
Wed Oct 22 09:09:54 EDT 2025
I doubt it. But attack forensics does seem like a good use for AI. The mix of tools and heuristics required is perfect for MoE and multiverse analysis. Browser-based vectors are a bit boring, though. Fake hot-spots and imsi catchers are more interesting.
At the hotel a couple of days ago, I borked my system trying to remove the persnickety pangpui, which was interfering with my ability to watch Netflix! So I had to re-install the OS and it would've taken forever to download all those newer packages over 5G. Luckily, there's not really any data on my laptop ... it's just a GUI for my other machines. So a keylogger would've got me, but not much else.
On 10/21/25 10:41 AM, Roger Critchlow wrote:
> Huh, I wonder if this signals the migration of AI dis-employed software talent into lives of crime?
>
> Or maybe it's just the same old same old software talent using ChatGPT to spice up their marketing copy.
>
> -- rec --
>
>
> On Tue, Oct 21, 2025, 9:11 AM glen <gepropella at gmail.com <mailto:gepropella at gmail.com>> wrote:
>
>
> https://www.trendmicro.com/en_us/research/25/j/how-vidar-stealer-2-upgrades-infostealer-capabilities.html <https://www.trendmicro.com/en_us/research/25/j/how-vidar-stealer-2-upgrades-infostealer-capabilities.html>
> > Key Takeaways:
> >
> > Vidar 2.0’s release coincides with a decline in Lumma Stealer activity, resulting in a spike in threat actor adoption and heightened campaign activity.
> > The new version is completely rewritten in C, introducing multithreaded architecture for faster, more efficient data exfiltration and improved evasion capabilities.
> > Enhanced credential extraction methods allowed Vidar 2.0 to bypass advanced browser security features, such as Chrome’s AppBound encryption, through direct memory injection.
> > Vidar 2.0 systematically targets a broad scope of data, including credentials from browsers, cloud services, cryptocurrency wallets, gaming platforms, and various communication apps such as Discord and Telegram.
> > Trend Vision One™ detects and blocks the specific IoCs referenced in this article, while providing customers with access to hunting queries, actionable threat insights, and intelligence reports related to Vidar Stealer.
>
--
¡sıɹƎ ןıɐH ⊥ ɐןןǝdoɹ ǝ uǝןƃ
ὅτε oi μὲν ἄλλοι κύνες τοὺς ἐχϑροὺς δάκνουσιν, ἐγὰ δὲ τοὺς φίλους, ἵνα σώσω.
More information about the Friam
mailing list