Today we will talk about a recently detected spyware called Vidar, but first things first. Spyware is similar to a gray area, as there is really no manual definition. However, as its name suggests, spyware is loosely defined as software designed to collect data from a computer or other device and forward it to a third party without the user’s knowledge or consent.

This new malware was detected being distributed via recent phishing campaigns using Microsoft’s HTML help files. Last week, Trustwave cybersecurity researcher Diana Lopera said the spyware was found in compiled HTML help (CHM) files of Microsoft sebanyak to avoid detection in spam email campaigns.

Vidar is a Windows spyware and information stealer that is often marketed by cybercriminals. Vidar may collect user and operating system data, online services and crypto accounts and credit card information.

Typically, this spyware is delivered via phishing and spam campaigns, but researchers have also discovered that this C++-based spyware is delivered via the PrivateLoader dropper and the Fallout exploit tool.

Based on information provided by Trustwave, the email campaigns Vida sends seem very traditional. The email contains a general subject line and an attachment called request.doc, which is basically an .iso file. The .iso file contains two files, namely, a CHM file pss10r.chm and an exe file called app.exe, so it is essential to be very careful with the emails that we open.


Deja un comentario

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *