Vidar Adds a Virtual Machine and Custom Ciphers to Obfuscate Strings

Summary
Zscaler ThreatLabz details how Vidar evolved from XOR and ChaCha-based string obfuscation to a per-build virtual machine and custom stream ciphers designed to hinder analysis.
Key points
- ThreatLabz tracked Vidar’s string-obfuscation changes from May to early September 2026, across internal versions 2.0 through 3.3.
- Vidar’s lightweight bytecode interpreter uses a one-byte accumulator and changing opcode handlers, constants, and substitution tables to deobfuscate strings.
- The VM also decrypts the key and nonce used to recover strings encrypted with Vidar’s custom stream cipher.
- Versions 2.0 and 2.1 use a modified ChaCha-based cipher; version 2.2 and later use per-build ARX-based stream-cipher variants.
- The changing algorithms and constants make static signatures and automated analysis more difficult, even though the obfuscation’s overall function remains similar.
- Zscaler reports sandbox and MDR detections for Vidar and provides sample hashes for several versions.
Article Details
- Defensive Notes
- ThreatLabz reports that Vidar changes VM opcodes, constants, substitution tables, and stream-cipher operations across builds, making static signatures and automated string analysis more difficult.
- The article recommends network and endpoint detection systems capable of keeping pace with Vidar's changing obfuscation.
- Zscaler reports sandbox detection and multilayered coverage under the threat name Win32.PWS.Vidar.
- Zscaler MDR reports the detection analytics WIN-BIN-NETCONN-TO-TELEGRAM-SHORTENED-URL, WIN-WEBBROWSER-UNUSUAL-PARENT, and WIN-STEALER-FILEMOD.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA256 | 1628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974 | Malware sample hash identified in the IOC table as Vidar v2.0. |
| SHA256 | 2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6 | Malware sample hash identified in the IOC table as Vidar v3.1. |
| SHA256 | 625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074 | Malware sample hash identified in the IOC table as Vidar v2.5. |
| SHA256 | 979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4 | Malware sample hash identified in the IOC table as Vidar v3.4. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationVidar hides strings using XOR, modified ChaCha-based encryption, and a custom bytecode VM combined with per-build stream ciphers; changing opcodes and constants hinder static and automated analysis.T1140 · Deobfuscate/Decode Files or InformationVidar interprets embedded bytecode to recover strings directly or recover keys and nonces subsequently used by custom stream ciphers to decrypt encrypted string arrays.