Advanced Vidar Stealer and XMRig Campaign Targets Consumers and SMBs
TL;DR
A recent campaign delivering Vidar stealer and the XMRig cryptocurrency miner has been identified, affecting consumers and small to medium-sized businesses, particularly in the U.S. and EU. Attackers employ malvertising tactics to direct victims to downloads disguised as cracked software, facilitating the infection process.
Main Analysis
Unit 42 researchers from Palo Alto Networks have detailed a financially motivated cyber campaign that has escalated since April 2026. This campaign utilizes malicious advertising to lure users into downloading password-protected archives containing malware masquerading as cracked versions of legitimate software. Upon execution, the loader binaries deploy both Vidar stealer, which captures sensitive data, and the XMRig miner, which utilizes victim CPU resources for cryptocurrency mining. The framework for these loaders is identified as Factory-v3, indicating a malware-as-a-service model.
Initial detection unveiled 43 loader binaries signed with a forged certificate from a legitimate entity, JustWatch GmbH. However, these signatures are not recognized by public trust stores, rendering the binaries untrusted when scrutinized by Windows’ SmartScreen. This approach exploits user trust in familiar branding despite the inherent risk of execution.
The malware also features advanced evasion techniques, including file size inflation through the addition of null bytes to bypass automated scanning and a method to patch the Antimalware Scan Interface (AMSI), effectively disabling detection mechanisms. This manipulation is achieved through an in-memory overwrite of critical functions, enabling the deployment of malicious payloads undetected.
Defensive Context
Organizations must be aware of the risks posed by this dual-threat campaign, especially those reliant on digital marketing and content distribution channels. Small and medium-sized businesses and consumers seeking cracked software are particularly vulnerable. Environments lacking robust security measures are at an elevated risk of falling victim to similar tactics, as malvertising targeting generic software names can easily mislead unsuspecting individuals.
Why This Matters
The financial motivation behind the malware, coupled with the targeted demographic of consumers and SMBs, creates a significant risk profile. Authentication data exfiltration through Vidar stealer can lead to credential theft, while XMRig mining consumes computational resources, potentially degrading system performance significantly.
Defender Considerations
The immediate focus for defenders should be on the indicators of compromise associated with this campaign. Entities should scrutinize outbound connections to the identified command-and-control servers. Identifiable C2 IP addresses include 116.203.243[.]208, 136.243.203[.]109, 136.243.203[.]111, and 138.199.246[.]13, alongside monitoring registry modifications that establish persistence mechanisms through run keys and scheduled tasks.
Indicators of Compromise (IOCs)
- C2 Server IPs:
- 116.203.243[.]208
- 136.243.203[.]109
- 136.243.203[.]111
- 138.199.246[.]13
- Malware File Paths:
- %TEMP%\MicrosoftUpdate.exe (Vidar stealer)
- %AppData%\Roaming\Microsoft\Windows\Temp\MicrosoftEdgeUpdate.exe (XMRig launcher)
- %AppData%\Roaming\Microsoft\Windows\Temp\NisSrv.exe (Persistence copy)
- Rogue Certificate Information:
- Subject: CN=justwatch[.]com
- Issuer: CN=WR3 (rogue self-signed CA)
Awareness and responsive measures are crucial for all stakeholders to mitigate the risks associated with this evolving campaign.






