Vidar Uses Custom Bytecode Interpreter and ARX Stream Ciphers for Per-Build String Obfuscation
Vidar stealer now hides strings with a custom bytecode VM and per-build ARX stream ciphers, weakening static detection.
Zscaler ThreatLabz says the Vidar infostealer, tracked since 2018, now hides embedded strings with a minimal custom virtual machine and per-build stream ciphers. From version 2.0 it uses a 14-handler bytecode interpreter; versions 2.0-2.1 use a modified ChaCha design, while 2.2 onward use an ARX cipher incorporating FNV-1a and the constant 0x9E3779B9. Changing opcodes, keys, and constants undermine static YARA matching. Splunk also observed sandbox and endpoint-security checks, and hashes are published for versions 2.0, 2.5, 3.1, and 3.4.