Vidar Infostealer Hammers SMBs via Malvertising Campaign
Incidents: Vidar infostealer and XMRig cryptominer target SMBs via malvertising, using fake cracked software downloads and advanced evasion tactics.
Deep Analysis and Expert Commentary
The attack chain begins with malvertising lures for pirated software, delivering password-protected archives containing a loader for Vidar and XMRig. Vidar harvests browser data, cookies, and crypto wallets, while XMRig hijacks CPU resources for Monero mining. The campaign's evasion techniques—including 500MB+ binaries to bypass sandbox limits and spoofed code-signing certificates—are tailored to circumvent SMB-grade defenses. The use of Factory-v3 suggests professionalization, with affiliates monetizing both stolen data and computational resources. Defenders should prioritize blocking C2 connections to pool.supportxmr[.]com, enforce strict Authenticode validation, and monitor for anomalous DLL loads. SMBs are particularly vulnerable due to typically weaker endpoint controls and less frequent security policy updates.
Action Items
- Block outbound connections to known C2 addresses and pool.supportxmr[.]com
- Enforce Microsoft Authenticode chain validation with certificate serial blocklisting
- Configure security tools to scan all files regardless of size and monitor nonstandard MpClient.dll loads
Original Article Brief Intro
Dark Reading · 2026-07-08 · Incidents: Vidar infostealer and XMRig cryptominer target SMBs via malvertising, using fake cracked software downloads and advanced evasion tactics.
Related Terms and Notes
Malware Families
- Infostealer
- Vidar — Infostealer malware targeting browser data, cookies, and cryptocurrency wallets, often distributed via MaaS platforms.
Techniques / TTPs
- XMRig — Open-source Monero mining software commonly repurposed for cryptojacking attacks.
Context Notes
- Authenticode
- Cryptojacking
- Factory-v3
- MaaS
- Malvertising
- Monero
- SMB
- Vidar
- XMRig