#ParsedReport #CompletenessMedium
08-09-2026
Peeling Back the Layers: Inside Vidar - From Virtualized Code to Stolen Credentials
https://www.splunk.com/en_us/blog/security/inside-vidar-from-virtualized-code-to-stolen-credentials.html
Report completeness: Medium
Threats:
Vidar_stealer
Antidebugging_technique
Victims:
Windows endpoints, Azure resources, Ftp servers
TTPs:
Tactics: 3
Technics: 12
IOCs:
File: 34
Registry: 3
Command: 1
Hash: 5
IP: 0
Domain: 0
Url: 0
Email: 0
BrowserExtension: 0
Soft:
Telegram, PccNTMon, Chrome, Chromium, hromium Ex, Windows Registry, Windows Security, Microsoft powershell, Slack
Functions:
ReadData
Win API:
NtQueryInformationProcess, NtGlobalFlag, GetComputerNameA, GetSystemInfo, SeDebugPrivilege, DuplicateHandle, RmStartSession, RmRegisterResources, RmEndSession
Win Services:
AvastSvc, ekrn, TmListen, NTRTScan, TmCCSF, MsMpEng
Languages:
python, powershell
Platforms:
x86, x64
Post #32291
90