A new and more advanced version of a well-known infostealer is making its appearance online, causing concern in the cybersecurity community. The Vidar 2.0 is spreading through hundreds of fake repositories on GitHub, as well as targeted posts on Reddit, taking advantage of users' trust in popular platforms. Under the guise of free cheats for popular online games, attackers manage to trap unsuspecting users and gain access to sensitive data.

Gamers are in the crosshairs of cybercriminals
The use of malware disguised as cheating softwareis not a new tactic. However, the systematic targeting of gamers has intensified significantly in recent years. Titles such as Counter-Strike 2, Fortnite, Valorant and Call of Duty are at the center of these attacks, as they have huge user bases and valuable digital assets.
Users looking for cheats are a particularly vulnerable group. They are often willing to ignore security warnings, disable antivirus , and run files with elevated privileges, believing that these actions are necessary for the software to function. This creates ideal conditions for the installation of malicious tools.
See also: LeakNet Ransomware group uses ClickFix techniques
The rise of Vidar 2.0 after the fall of other infostealers
According to Acronis, the spread of Vidar 2.0 is directly linked to the recent neutralization of other well-known infostealers, such as Lummastealer and Rhadamanthys. The gap created in the malware "market" seems to be quickly filled by new, more sophisticated threats.
At the same time, attackers are demonstrating increased capabilities in abusing trusted platforms. Hosting payloads and landing pages on GitHub lends credibility to campaigns, reducing victims' suspicion and increasing success rates.
Πώς λειτουργεί η επίθεση στην πράξη
The infection process begins with a seemingly legitimate installation page, which guides the user step by step. The instructions include disabling antivirus, decompressing encrypted files, and running programs as administrator. These practices, while suspicious, are considered common in the cheating world.

The initial payload is a PowerShell script that is converted into a .NET executable. Once executed, it creates exceptions in Windows Defender, allowing additional malicious files to be installed unhindered. It then communicates with encrypted addresses to download the next stage of the attack.
The final payload is installed in a hidden folder on the system and executed as “background.exe”, while a persistence via scheduled tasks, ensuring that the malware will be launched at every login.
See also: Konni Group exploits KakaoTalk to spread EndRAT Malware
Concealing infrastructure and difficulty of detection
One of the most concerning aspects of Vidar 2.0 is the way it hides its command-and-control (C2) infrastructure. Instead of fixed servers, it uses Telegram bots and Steam profiles as intermediate “nodes” to retrieve instructions.
This approach makes it extremely difficult to detect and block malicious activity, as it relies on legitimate and widely used services. At the same time, the malware is packaged with obfuscation techniques, further complicating analysis.
The risks for users and organizations
The consequences of a Vidar 2.0 infection are severe. The malware can steal credentials, cookies, browser data, cryptocurrency wallet information, and other sensitive data. For organizations, this can lead to network breaches, financial losses, and the leakage of critical information.
The use of personal computers for work further increases the risk, as an infected system can become an entry point into corporate networks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Cybersecurity protection measures and good practices
Addressing such threats requires a combination of technology solutions and user awareness. Using advanced EDR tools can help identify suspicious behaviors, such as unusual processes or unauthorized data access.
See also: GlassWorm attack: Stolen GitHub tokens used to insert malware into Python repos
At the same time, it is crucial to keep systems up to date and implement policies that restrict the execution of files from untrusted locations like AppData. Most importantly, however, is a change in mindset: users should avoid downloading software from unofficial sources, even if it promises an "advantage" in a game.
