Security researchers are warning that Vidar Stealer infections are likely to increase after the release of a new version , which promises upgraded features and better performance. The malware's creator announced this year that Vidar 2.0 has been rewritten in C, supports parallel data theft via multiple threads, and includes more advanced obfuscation and analysis evasion mechanisms.

Technical improvements that change data
The move from C++ to C reduced dependencies and executable size, while improving execution speed and raw performance. At the same time, Multi-thread CPU support allows the malware to create parallel data-stealing worker threads, which collect data faster and reduce the time spent on the infected machine. The Builder adds polymorphism options with control-flow flattening and complex numerical state-machine switch constructs, making static detection by security tools more difficult.
See also: WhatsApp warns of screen sharing scams
Bypassing Chrome's protections
One of the most concerning features of the new Vidar 2.0 release is its encryption Chrome's App-Bound via memory injection techniques. The malicious payload launches the browser with debugging enabled and injects code into processes, extracting encryption keys directly from memory. Instead of attempting to decrypt stored objects, it steals the active keys — a technique that has proven effective in other infostealers.
Targets and methods of dissemination
Vidar 2.0 aims to steal cookies, autofill fields, crypto wallet extensions, cloud credentials, Steam accounts, Telegram and Discord data. After collecting them, it captures screenshots, compresses and exports the data to delivery channels such as Telegram bots and URLs stored in Steam profiles — making it difficult to detect and immediately isolate.

Market competition: Lumma declines, Vidar rises
The launch of Vidar 2.0 coincided with the decline in Lumma Stealer activity following a doxxing campaign against Lumma operators. This leaves a gap in the market that analysts say Vidar can fill: its technical capabilities, track record since 2018, and competitive pricing make it a likely successor to the infostealer supply chain.
Impact on businesses and end users
Improved capabilities and obfuscation techniques increase the risk of widespread collection of sensitive data before detection systems. Businesses without multi-factor access control or with inadequate password management policies are particularly vulnerable. Targeting desktop cryptocurrency wallets increases the financial risk for users with assets in such wallets.
See also: AI-powered ransomware attacks: The top security concern
What can organizations do now?
Enhance memory and process forensics, monitor network anomalies, and implement rapid process isolation. Enable MFA, use password managers, restrict app permissions , and avoid installing unauthorized extensions. Organizations should also maintain up-to-date anti-malware systems and monitor unwanted browser launches with debugging flags.

Strengthening the response and policies
The bigger picture shows changes: stealer creators are selling complete packages with builder, support and delivery channels, lowering the technical barrier for new attackers. This gives smaller groups access to advanced tools. Law enforcement enforcement remains necessary but often slow. That’s why organizations need to invest in effective technical and human protection measures to prevent an infection. Response time is critical.
See also: Salt Typhoon breached a European Telecom Network with Snappybee malware
Vidar 2.0 is not just an update — it signals a maturation of tools and services in the digital underworld. The tech community and businesses must respond with technical and organizational measures, because the battle to protect digital assets is now becoming more complex.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
