Date: 09/25/2026
Severity: Medium
Summary
Vidar is an information-stealing malware first observed in 2018 that has continued to evolve its string obfuscation techniques. Its developers have modified deobfuscation algorithms, constants, and primitives to make detection and analysis more difficult. From May to early September 2026, ThreatLabz tracked Vidar’s progression from basic XOR-based obfuscation to ChaCha20. More recently, Vidar adopted a custom virtual machine (VM) executed through a lightweight bytecode interpreter. The VM is combined with a custom stream cipher that changes with each malware build, further complicating analysis.
Indicators of Compromise (IOC) List
Hash | 1628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974
625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074
2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6
979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | sha256hash IN ("1628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974","625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074","979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4","2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6")
|
Reference:
https://www.zscaler.com/blogs/security-research/vidar-adds-virtual-machine-and-custom-stream-ciphers-string-obfuscation#introduction