Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 64-bit Windows platform, family Vidar
This detection identifies the Vidar trojan, a potent information stealer designed to exfiltrate sensitive data from the infected system. It targets web browser credentials, cookies, cryptocurrency wallets, and other personal files, sending the stolen information to a remote attacker. The !MTB suffix indicates this was identified via machine learning behavioral analysis.
No detailed analysis available from definition files.
ddca542e034bc9d6b576ee632f2f833fe2df77e56122cbef084a1f9882e2917fIsolate the host from the network immediately. Run a full scan with an updated antivirus solution to remove the threat. Since Vidar is an information stealer, reset all user passwords and credentials that were stored or used on this machine. Investigate the initial access vector to prevent re-infection.