[FRIAM] Vidar Stealer 2.0

glen gepropella at gmail.com
Wed Oct 22 09:09:54 EDT 2025


I doubt it. But attack forensics does seem like a good use for AI. The mix of tools and heuristics required is perfect for MoE and multiverse analysis. Browser-based vectors are a bit boring, though. Fake hot-spots and imsi catchers are more interesting.

At the hotel a couple of days ago, I borked my system trying to remove the persnickety pangpui, which was interfering with my ability to watch Netflix! So I had to re-install the OS and it would've taken forever to download all those newer packages over 5G. Luckily, there's not really any data on my laptop ... it's just a GUI for my other machines. So a keylogger would've got me, but not much else.

On 10/21/25 10:41 AM, Roger Critchlow wrote:
> Huh, I wonder if this signals the migration of AI dis-employed software talent into lives of crime?
> 
> Or maybe it's just the same old same old software talent using ChatGPT to spice up their marketing copy.
> 
> -- rec --
> 
> 
> On Tue, Oct 21, 2025, 9:11 AM glen <gepropella at gmail.com <mailto:gepropella at gmail.com>> wrote:
> 
> 
>     https://www.trendmicro.com/en_us/research/25/j/how-vidar-stealer-2-upgrades-infostealer-capabilities.html <https://www.trendmicro.com/en_us/research/25/j/how-vidar-stealer-2-upgrades-infostealer-capabilities.html>
>      > Key Takeaways:
>      >
>      >     Vidar 2.0’s release coincides with a decline in Lumma Stealer activity, resulting in a spike in threat actor adoption and heightened campaign activity.
>      >     The new version is completely rewritten in C, introducing multithreaded architecture for faster, more efficient data exfiltration and improved evasion capabilities.
>      >     Enhanced credential extraction methods allowed Vidar 2.0 to bypass advanced browser security features, such as Chrome’s AppBound encryption, through direct memory injection.
>      >     Vidar 2.0 systematically targets a broad scope of data, including credentials from browsers, cloud services, cryptocurrency wallets, gaming platforms, and various communication apps such as Discord and Telegram.
>      >     Trend Vision One™ detects and blocks the specific IoCs referenced in this article, while providing customers with access to hunting queries, actionable threat insights, and intelligence reports related to Vidar Stealer.
> 
-- 
¡sıɹƎ ןıɐH ⊥ ɐןןǝdoɹ ǝ uǝןƃ
ὅτε oi μὲν ἄλλοι κύνες τοὺς ἐχϑροὺς δάκνουσιν, ἐγὰ δὲ τοὺς φίλους, ἵνα σώσω.




More information about the Friam mailing list