Cyber Security News

Vidar & StealC 2.0 Released by Threat Actors With a Complete New Build

Threat actors have simultaneously released major updates for two prominent info-stealers, Vidar and StealC, marking their transition to version 2.0. 

These updates, announced in late February 2025, introduce redesigned builds, modernized features, and enhanced capabilities. 

However, cybersecurity experts have uncovered an intriguing overlap: both malware strains appear to share portions of their codebase, raising concerns about potential code theft or collaboration among cybercriminals.

Key Features of Vidar and StealC 2.0

According to @g0njxa post on X, both Vidar and StealC have undergone substantial upgrades in their latest versions, as highlighted in their respective announcements:

Modernized User Interfaces: Both malware families now feature updated interfaces, likely aimed at improving usability for operators.

Rewritten Builds: The codebases for both projects have been rewritten from scratch, purportedly using modern methods to enhance functionality while avoiding reliance on older code.

New Upgrades to Vidar & StealC 2.0

Improved Runtime Stability: A new “morpher” module has been introduced to improve runtime stability and accelerate malware execution processes.

Enhanced Marketing and Support: Threat actors behind these projects have emphasized improved support services in multiple languages, signaling a push toward broader adoption by cybercriminals.

Despite being marketed as distinct projects, researchers have identified significant similarities between Vidar 2.0 and StealC 2.0 at the code level. 

Screenshots of internal discussions among developers suggest that Vidar’s creators suspect their code may have been stolen and repurposed by other actors. 

For instance, one developer remarked, “Did someone steal my cookie extractor or something?” This suspicion aligns with technical findings showing identical modules for cookie extraction and injection failure handling.

Vidar has been a formidable info-stealer since its emergence in 2018. Written in C++, it is capable of exfiltrating sensitive data such as browser cookies, saved passwords, cryptocurrency wallets, and even two-factor authentication files. 

Its operators frequently use social media platforms like Telegram and Mastodon to retrieve Command-and-Control (C2) information via profile descriptions—a technique known as “dead drop.”

This method allows rapid updates to C2 infrastructure while evading detection.

StealC is a relatively newer player but has quickly gained traction due to its modular architecture and ease of customization.

Like Vidar, it targets sensitive user data but also includes advanced obfuscation techniques to evade detection.

Implications for Cybersecurity

The simultaneous release of Vidar and StealC 2.0 underscores the increasing sophistication of info-stealer malware. 

The shared codebase complicates attribution efforts and suggests either collaboration or intellectual property theft within the cybercriminal ecosystem.

Detection strategies must evolve to address these threats effectively. YARA rules targeting shared modules can serve as a starting point for identifying infections:

Detection rule for Vidar and StealC (Source: @RussianPanda9xx shared on X)

The release of Vidar and StealC 2.0 marks a pivotal moment in the evolution of info-stealer malware. 

While these updates enhance the capabilities of both malware families, the discovery of shared code raises critical questions about the dynamics within the cybercriminal community. 

Organizations must remain vigilant by employing advanced detection mechanisms to mitigate the risks posed by these increasingly sophisticated threats.

Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

4 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

10 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

15 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

26 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago