INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Vidar Takes Top Spot in Infostealer Market Amid Chaos
| 2026-04-28 19:07 CRITICAL LOW DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
In April 2026, Vidar, a credential-stealing malware, rose to the top of the infostealer market on Russian Market after law enforcement disrupted its two biggest rivals in May and November 2025. The shift was fueled by Vidar's calculated release of an upgrade and expansion of its distribution network during this time period. As a result, Vidar has displaced Lumma and Rhadamanthys as the most used infostealer on Russian Market since November 2025. This malware targets sensitive data from major browsers and cryptocurrency wallets, allowing attackers to take over accounts, move laterally inside networks, deploy ransomware, escalate privileges, and execute other malicious actions under a legitimate user or service guise. Vidar is distributed through various tactics, including phishing attachments disguised as software installers, social engineering lures on YouTube, ClickFix campaigns, Trojanized npm packages, and fake game cheats.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
RU
cryptocurrencycryptocurrency
Incident Timeline
November 2025
Threat actors using Vidar, a high-volume credential harvester, monetized stolen credentials on Russian Market and other underground marketplaces.
Click on any entity below to view its context and source!
threat_actor
Scattered Spider
The shift is significant because Vidar is a high-volume, broad-spectrum credential harvester that some high-profile threat groups, including
Scattered Spider
, have used in their campaigns.
2026/04/28
Threat actors successfully profited from the instability resulting from the takedowns of Lumma and Rhadamanthys, allowing Vidar to rise to the top of the infostealer ecosystem on the Russian Market.
Click on any entity below to view its context and source!
infrastructure
Windows
Related:
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
Intrinsec's recommendations for protecting against Vidar include enabling multifactor authentication for browser-related accounts to mitigate credential theft, deploying D…
infrastructure
Linux
Related:
Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug
"Chaos is a ladder and Vidar successfully profited of the instability resulting from the takedowns of Lumma and Rhadamanthys, to rise to the top of the infostealer ecosystem," t…
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Related:
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
Intrinsec's recommendations for protecting against Vidar include enabling multifactor authentication for browser-related accounts to mitigate credential theft, deploying D…
Metrics
infrastructure
Linux
Affected Product
Related:
Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug
"Chaos is a ladder and Vidar successfully profited of the instability resulting from the takedowns of Lumma and Rhadamanthys, to rise to the top of the infostealer ecosystem," t…
Intelligence Sources
Dark Reading
2026-04-28
Vidar Rises to Top of Chaotic Infostealer Market
Dark Reading
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:43
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Intrinsec
entity
5x
timeline
Temporal Reference
November 2025
date
4x
tactic
Cyber Operation Type
Ransomware
tactic
2x
infrastructure
Affected Product
Windows
software
2x
tactic
MITRE ATT&CK Technique
T1592.002 - Software
technique
Contextual Telemetry
Context Block
4 METRICS
target region
Target Country
Russian Federation
country
source region
Origin Country
France
country
threat actor
APT Group
Scattered Spider
actor
general metric
Security Flaws
38
security flaws
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.