Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation

    Date: 09/25/2026

    Severity: Medium

    Summary

    Vidar is an information-stealing malware first observed in 2018 that has continued to evolve its string obfuscation techniques. Its developers have modified deobfuscation algorithms, constants, and primitives to make detection and analysis more difficult. From May to early September 2026, ThreatLabz tracked Vidar’s progression from basic XOR-based obfuscation to ChaCha20. More recently, Vidar adopted a custom virtual machine (VM) executed through a lightweight bytecode interpreter. The VM is combined with a custom stream cipher that changes with each malware build, further complicating analysis.

    Indicators of Compromise (IOC) List

    Hash

    1628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974

    625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074

    2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6

    979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    sha256hash IN ("1628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974","625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074","979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4","2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6")

    Reference: 

    https://www.zscaler.com/blogs/security-research/vidar-adds-virtual-machine-and-custom-stream-ciphers-string-obfuscation#introduction


    Tags

    MalwareVidarStealerObfuscation

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags