IOC Radar
TLP:WHITE1 IOC

Vidar Malware Bypasses Chrome Encryption Using CryptUnprotectMemory

CP
Cyber Press
Published June 20, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREunknownCAPABILITYVidarVICTIMunknown
Adversary
Infrastructure
Capability(1)
Victim

Attack Flow6 steps · MITRE ATT&CK mapped

ExecutionTA0002·T1055
1/6
Process Injection
ActionFork browser process
Vidar opens a handle to the Chrome process and creates a silent, threadless fork of the browser using NtCreateProcessEx.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise1

TypeIndicatorConfidenceScoreFirst Seen
SHA256459daa809751e73f60fbbe4384a7d1653c36bb06945e4eb3635270924241100a
file-hashintel-blogmalware
High
86
Jun 19, 26

IOC Relationship Graph

IOC Relationship Graph1 total IOCs
SHA256
SHA2561Malware1REPORTVidar Malware Bypasses ChrVidar
scroll to zoom · drag to pan · click IOC to open