Vidar Infostealer Hammers SMBs via Malvertising Campaign

Threat Actors Unleash Double Whammy Malware Campaign on Small Businesses

A financially motivated group is exploiting small to midsize businesses (SMBs) globally with a sophisticated malvertising campaign that delivers two payloads in one: the Vidar infostealer and a cryptominer called XMRig. The attackers use lures of pirated or cracked software to entice victims into downloading malicious files, which then unleash a malware loader that drops both Vidar and XMRig onto compromised systems.

The campaign, uncovered by Palo Alto Networks’ Unit 42 in April, targets consumers and SMBs worldwide with its multifaceted delivery and evasion strategies. The attackers impersonate legitimate software download sites to trick victims into executing password-protected archives that contain the malware loader. Once executed, the loader bypasses security defenses using techniques like an in-memory Antimalware Scan Interface (AMSI) bypass, before deploying Vidar and XMRig.

Vidar is a notorious infostealer that targets browser credentials, cookies, and crypto wallets, while XMRig mines Monero cryptocurrency in the background, quietly hijacking victim CPU cycles for its own profit. The attack flow is cleverly designed to evade detection by automated analysis tools, making it difficult for SMBs to spot the malware before it’s too late.

The malware delivery mechanism itself appears to be a side hustle for the operators, who also offer a separate upstream service called Factory-v3 framework for MaaS building. This framework allows them to generate unique binaries per build, making detection even more challenging. The attackers also sign the loader with a fabricated certificate and use padding with null bytes to evade automated analysis.

The campaign’s dual-monetization scheme is particularly worrying, as it shows how financially motivated threat actors are increasingly combining multiple monetization strategies in a single infection to maximize profits. Vidar credentials and session cookies are sold on criminal log markets, while XMRig provides passive income from hijacked victim CPU cycles.

SMBs must be especially vigilant against these types of attacks, as they appear specifically tuned for SMB-grade defenses. To fortify their defenses, businesses should implement robust email gateway scanning and automated sandbox detonation to prevent the initial download. Additionally, regular security audits and threat intelligence monitoring can help detect and respond to such threats before they cause significant damage.

In light of this campaign, SMBs must prioritize cybersecurity awareness and education for employees, ensuring that everyone is on the lookout for suspicious online ads and downloads. By staying informed and vigilant, businesses can protect themselves against these sophisticated attacks and minimize the risk of a successful infection.


Source: Dark Reading — 2026-07-08