Vidar info-stealing malware spreads via 1,300 domains impersonating AnyDesk site

Share post:

Attackers are spreading Vidar information stealing malware using 1,300 domains impersonating AnyDesk official site. The malicious activity was uncovered by SEKOLA threat analyst crep1x. Crep1x shared the complete list of the malicious hostnames all of which linked to the same IP address of 185.149.120[.]9.

The malicious hostnames include typosquats for AnyDesk, MSI Afterburner, 7-ZIP, Blender, Dashlane, Slack, VLC, OBS, cryptocurrency trading apps, and others.

According to the researcher, the cloned sites pretended to be an installer for the AnyDesk software, and they were distributing a ZIP file named ‘AnyDeskDownload.zip.’ The installer then installs Vidar stealer instead of installing the remote access software.

After installation, the malware steals victims’ browser history, account credentials, saved passwords, cryptocurrency wallet data, banking information, and other sensitive data. The data will then be sent back to the attackers who could use it for other malicious activities.

To avoid clicking on promoted results (ads) in Google Search, users are advised to bookmark the sites they use for downloading software. They are also advised to find the official URL of a software project from their Wikipedia page or their OS’s package manager.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Cloudflare Launches Open Source Tool for Secure, Keyless SSH Authentication

Cloudflare has released an open-source tool called OPKSSH (OpenPubkey SSH), which allows developers and IT teams to use...

US Defence Contractor Fined 4.6 Million For Failing To Meet Cyber Security Requirements.

A U.S. defence contractor, MORSE Corp, has agreed to pay $4.6 million to settle allegations of failing to...

Tech Aide on U.S. Government Efficiency Team Linked to Cybercrime Group

A 19-year-old staffer working on the U.S. Department of Government Efficiency (DOGE) initiative has been linked to a...

Top U.S. Security Officials Have Even More Data Exposed Through Public Apps, Chats, and Data Leaks

A new investigation has revealed that personal information belonging to senior U.S. security officials — including active phone...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways