Vidar Malware Using New Tactics to Evade Detection and Anonymize Activities
Threat actors behind the Vidar malware are actively evolving their backend infrastructure to conceal their operations and evade detection. By rotating IP addresses and leveraging VPNs alongside TOR relays, they aim to anonymize management activities within general internet traffic, effectively hiding their digital footprint amidst legitimate user noise. The malware operators have also segmented their infrastructure, separating access for regular customers from that of the management team and premium users. This restructuring, coupled with the implementation of mandatory authentication for previously public file downloads, indicates a strategic effort to tighten security around their command-and-control systems and restrict unauthorized access to their stealer’s capabilities. This analysis is crucial for open data researchers as it demonstrates how commercial malware ecosystems adapt their technical architecture in response to scrutiny. Understanding these infrastructure shifts helps the security community track emerging threats, refine detection models, and maintain transparency regarding the operational tactics of cybercriminal groups, thereby supporting broader efforts to map and mitigate the digital threat landscape.
Source: thehackernews.comPublished on 2023-06-16
Related news
- The National Anti-Corruption Commission (NACC) Thailand Emphasized Open Data Are Anti-Corruption Weaponry In Digital Age
- Arkansas AG Tim Griffin forms group to consider possible changes to state's Freedom of Information Act
- Hillary Clinton’s E-mail From Sid “France’s client & Qaddafi’s gold” – Unclassified (FOIA)
- iGA Chief launches Beta Version of revamped Bahrain Open Data Portal | THE DAILY TRIBUNE | KINGDOM OF BAHRAIN
- ¿Y el INAI?, Alejandro Armenta pedirá licencia en el Senado para buscar gubernatura de Puebla