A financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining.
July 8, 2026
Threat actors are targeting consumers and small to midsize businesses (SMBs) globally in a financially motivated malvertising campaign that delivers the Vidar infostealer and cryptomining malware with multifaceted delivery and evasion strategies.
Researchers from Palo Alto Networks' Unit 42 uncovered the campaign in April; it lures victims to pages for downloading files that impersonate cracked versions of copyright-protected software, according to a report published July 7. The files delivered, however, are actually password-protected archives that hide a malware loader for dropping and executing both the Vidar infostealer and the open source XMRig cryptominer. Vidar targets browser credentials, cookies, and crypto wallets, while the XMRig mines Monero cryptocurrency.
While the attack follows a typical playbook for malvertising, the campaign stands out for both its delivery mechanism and evasion strategies, which point to an experienced affiliate of the Vidar malware-as-a-service (MaaS) operation, which primarily operates in the US and Europe, according to Unit 42 threat researchers Bharath Nannaka and Pranay Kumar Chhaparwal.






