Malicious Campaign Distributes Vidar Infostealer and Monero Mining Malware (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Campaign first detected in April 2026 by Unit 42 targeting global consumers and SMEs.
- Malware delivered via password-protected .bin archives impersonating cracked software.
- Vidar steals credentials and crypto wallet data; XMRig mines Monero on victim machines.
- Uses Factory-v3 MaaS framework and Telegram C2 with 'X3D MINER' tag.
"Unit 42 researchers identified a campaign targeting consumers and SMEs worldwide. Attackers use malvertising to deliver password-protected archives mimicking cracked software. The loader drops Vidar infostealer and XMRig cryptocurrency miner. Vidar steals credentials and crypto wallet data, while XMRig hijacks CPU cycles to mine Monero. The campaign employs Factory-v3 malware framework and Telegram for C2. Over 99 loader samples were found. The dual monetization scheme sells stolen data and mines cryptocurrency."
no comments yet.