Vidar Adds a Virtual Machine and Custom Ciphers to Obfuscate Strings

· Original article ↗

Summary

Zscaler ThreatLabz details how Vidar evolved from XOR and ChaCha-based string obfuscation to a per-build virtual machine and custom stream ciphers designed to hinder analysis.

Key points

  • ThreatLabz tracked Vidar’s string-obfuscation changes from May to early September 2026, across internal versions 2.0 through 3.3.
  • Vidar’s lightweight bytecode interpreter uses a one-byte accumulator and changing opcode handlers, constants, and substitution tables to deobfuscate strings.
  • The VM also decrypts the key and nonce used to recover strings encrypted with Vidar’s custom stream cipher.
  • Versions 2.0 and 2.1 use a modified ChaCha-based cipher; version 2.2 and later use per-build ARX-based stream-cipher variants.
  • The changing algorithms and constants make static signatures and automated analysis more difficult, even though the obfuscation’s overall function remains similar.
  • Zscaler reports sandbox and MDR detections for Vidar and provides sample hashes for several versions.

Article Details

Defensive Notes
  • ThreatLabz reports that Vidar changes VM opcodes, constants, substitution tables, and stream-cipher operations across builds, making static signatures and automated string analysis more difficult.
  • The article recommends network and endpoint detection systems capable of keeping pace with Vidar's changing obfuscation.
  • Zscaler reports sandbox detection and multilayered coverage under the threat name Win32.PWS.Vidar.
  • Zscaler MDR reports the detection analytics WIN-BIN-NETCONN-TO-TELEGRAM-SHORTENED-URL, WIN-WEBBROWSER-UNUSUAL-PARENT, and WIN-STEALER-FILEMOD.

Indicators of compromise

TypeIndicatorContext
SHA2561628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974Malware sample hash identified in the IOC table as Vidar v2.0.
SHA2562d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6Malware sample hash identified in the IOC table as Vidar v3.1.
SHA256625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074Malware sample hash identified in the IOC table as Vidar v2.5.
SHA256979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4Malware sample hash identified in the IOC table as Vidar v3.4.

MITRE ATT&CK

Malware

Vendors

Products

Related Articles