Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
A financially motivated campaign utilizing Vidar stealer and XMRig cryptocurrency miner has been active since April 2026, targeting consumers and small- and medium-sized businesses globally, primarily in the U.S. and EU. The campaign leverages malvertising to distribute loader binaries that impersonate cracked software, ultimately delivering Vidar stealer and XMRig. The operators are distributing loader binaries through a MaaS affiliate network, utilizing the Factory-v3 builder, a custom Go toolchain, and a fabricated Authenticode certificate to bypass security measures. The campaign employs anti-forensic techniques and is linked to a concurrent Lumma stealer campaign, highlighting the use of Factory-v3 as a service for multiple stealer affiliates.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
