Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
A financially motivated campaign active in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide via malvertising for fake software cracks. The campaign uses the Factory-v3 Go loader framework with per-build unique binaries, fabricated Authenticode certificates impersonating legitimate brands, file-size inflation up to 491 MB to evade sandbox analysis, and an in-memory AMSI bypass. Vidar exfiltrates browser credentials, cookies, and crypto wallets to C2 servers, while XMRig mines Monero using the pool.supportxmr.com mining pool. The operator receives Telegram notifications for each new infection.
- domainpool[.]supportxmr[.]comXMRig Monero mining pool used by the campaign for cryptocurrency mining; article recommends blocking outbound connections
- filenameFEbJCNWOCKMJ.batAttacker-named startup batch script for persistence; placed in Windows StartUp folder to launch NisSrv.exe on boot
- filenamemgwthmc2.datAttacker-named XMRig Monero configuration file dropped to %AppData%\Roaming\Microsoft\Windows\Temp; built in memory before being written to disk
- filenameMicrosoftEdgeUpdate.exeXMRig launcher dropped to %AppData%\Roaming\Microsoft\Windows\Temp; launched with --config=mgwthmc2.dat argument
- filenameMicrosoftUpdate.exeVidar stealer component dropped to %TEMP%; mimics Windows Update binary name; targets browser credentials, cookies, and crypto wallets
- ip116[.]203[.]243[.]208Vidar C2 server identified in Variant B cluster (April 24, 2026)
- ip136[.]243[.]203[.]109Primary Vidar stealer C2 server; receives exfiltrated browser credentials, cookies, and crypto wallet data over port 443
- ip136[.]243[.]203[.]111Vidar C2 server identified in Variant B cluster
- ip138[.]199[.]246[.]13Vidar C2 server identified in Variant B cluster
- md51aae8bf580c846f39c71c05898e57e88Imphash for Cluster C x86 EXE Go loaders (3 samples, shared with Lumma Stealer campaign)
- md5c10333c92889b65c3590ef2b3819b420Imphash for Cluster D Vidar core payload (1 sample)
- md5d42595b695fc008ef2c56aabd8efd68eImphash for Cluster A x64 EXE Go loaders (26 samples)
- md5d8b31f8c03e0c76ff245ed05a15ffe6cImphash for Cluster B x64 DLL fake MpClient.dll sideload loaders (13 samples)
- sha1ab92f731ab20774dfdb95664ee41a2fbafe2a284SSL certificate SHA1 fingerprint of Vidar C2 server 136.243.203.109; listed on Abuse.ch SSL blocklist
- sha25603e6f4f49cec3af38bbec9ed64c195c7a85a630ec989efb3669f04a2993c1dd7Cluster C x86 EXE Go loader sample (shared with Lumma Stealer campaign)
- sha256097a87cfa4a5186aba3bba096866692951bde59c6f0c2e8c1c4a599246d14da8Cluster A x64 EXE Go loader sample
- sha2560a6a67a2fc4d79ec1cd8afc5b8b7a5e69a406e53d57a7334e097c5d0644de5f6Cluster B x64 DLL fake MpClient.dll sideload loader sample
- sha25615489bcd6e4602b41c9a787ec8d7ab027d5e45d400938048bb1c702ad5937980Variant B loader sample (Bleacher Report certificate impersonation)
- sha256169a330353e53a409e0109c914404354741ff1e1c64e501738dc05e58ea92abcVariant B loader sample
- sha256201594c9d173bba6cb509407ecba378c19b93da0a81a2182a913c480e6dbb54eCluster A x64 EXE Go loader sample
- sha25620bf39e1e67152039e70a01ad9e7b23c08d23d2a724ef9c44903f3d4353a2275Cluster A x64 EXE Go loader sample
- sha2562a02ec4af5ed591afdf1236a443e3b68642ee133f38a2857d1eada51246ab498Variant B loader sample
- sha2562b7297a5f502a2e9a59066f0a370bc5a8b28addd0e27975db3d770f801c15397Variant B loader sample
- sha2562c0b344af415b787b396c8e23bbeb112bd471a1ca1d12cf357c48e2ee1ae068cVariant B loader sample
- sha2562c6e8f86c05781af12b323311e83e011f1a603928e2086c48e2ca59e33d90dbeVariant B loader sample
- sha2562e11a16f94484e0f43eb4572f800f26f0b4a1314cbdae3c44c1ae35f376906d8Variant B loader sample
- sha2562f1400a91c853d61622f4d21ed97d96ea1093c0fa1586669bea6f6baa331251fVariant B loader sample
- sha256314ce675c040c63b825f213965f5c76a3bd09bf70e138708367e2a84e9e84b30Variant B loader sample
- sha25632172e4d8d2ab9fb29b36c9b279117be6ff611b5b91ff7b1c42501a5ec969f2bVariant B loader sample
- sha256330efeebba3782994612fdfe20ff96c930af33a83b88a342b6622461511921b2Variant B loader sample
- sha25635b51bbe42edd15918b015eaa1b4f0e6b5c94f186d71d887e39f1da69a4dec3fVariant B loader sample
- sha25635dde1b2482b12582820a861e7c46f10721af6b75052fc872c05d2230a4e8ca1Cluster A x64 EXE Go loader sample
- sha2563c3f12531045b7eedfe25e0f291d4792b0d8c8366f8de043e2fa8ecf34ccb913Variant B loader sample
- sha2563db33b0423bb9278db267a7adb036ecbd6aeebd7909d06d824919708b1e12e1bVariant B loader sample
- sha2563e906ae47e9836a591f44d4b743e961d634a404fa8fd8bfae64f1d54c853be2bVariant B loader sample
- sha25643920ef7d2742d140a1ab2a1ef172c716903474c73561377dc4f1534d2c5f581Cluster A x64 EXE Go loader sample
- sha25647d6d1a38534ba897a5a1e293e3d5df303bbd8e0526e756ad08887ffc1417befCluster A x64 EXE Go loader sample
- sha256488d941b7b4428b0f4a0e5495e3857b9b96215fb3e7f164b06640d59096425e6Cluster B x64 DLL fake MpClient.dll sideload loader sample
- sha2564bf770a59d367b532dec32668f86003b17d93918dba5ef5fd2b19c5394252436Variant B loader sample
- sha2564f456142caf590d98fb11ca247800bb417766714527e5a4707ac2f5d01542626Variant B loader sample
- sha25653d263b292be387843fadb7131c2d538b4262c81f5b95cfacafacf2d5446c06eVariant B loader sample
- sha2565494909e0f5221db75e933b28981b2d0e118f227b7d8a5980d88b500b76dfc2eVariant B loader sample
- sha25654dc05ab56244444f86d69b8274a6075906f7ba2307b08e08d3884abde255495Variant B loader sample
- sha256559f46ceb801a3540eace594476718e1486b5b4423cfb4ff64530ff8fb4a3815Variant B loader sample
- sha2565838ae6c748dcbdfa13c6529c654cb821897d29835d3e7e05ca23fb2f3794f02Variant B loader sample
- sha25659b9153c4e9e155c976db1a2fd4d1b28fa10bb9c4dcafdc4758b352c037e3d86Variant B loader sample
- sha2565b6a466b65d479b77a03b15a95ac097b45e23ff7ae5ef6282985b2a503deb691Variant B loader sample
- sha2565d7324d8b5a25f862ef8223c6766d0e80af3ad168e17312b265e13a3a68e0dedCluster B x64 DLL fake MpClient.dll sideload loader sample
- sha256613e5314a7ded3155cdec49fd34e852e181f4651d78bd8bf3adad2f4dbf22b0dVariant B loader sample
- sha25662877a5096828c4bc2fca7cbee7d38b11a0c90fd0d3fc8c37981581e9988c919Variant B loader sample
- sha256634e89d8592d7c9e2bc1c098217a813947b44a4f80bc569e9a15c1e8b0864b91Variant B loader sample
- sha25667569adec99fd38b114ae07e2e549e6c16f75368f3c5373022c84934ed1c8e84Variant B loader sample
- sha25668ced9d7c1b1ff8ffb5f56c7d3f849d4fd16a1b95324426811424b40043d6d25Cluster A x64 EXE Go loader sample
- sha2566b7ff061eebeb9ead8812c410247768a7ba90786aeeb1bafa6412cc5b08237b5Cluster A x64 EXE Go loader sample
- sha2566d49233b1fca22f3823e856e4c16749e9c45f384ea57055fead16df35b217226Variant B loader sample
- sha25671c79e8bf71ed257435ea9b8b91e118ba03ec681860651190f7d7457804313eeVariant B loader sample
- sha256739cdedb20de39aeb1f15dc8c2dbbf15fa993250fd879bf87443ff9aeaf4997bCluster A x64 EXE Go loader sample
- sha25674df77b6a83d89fa137fd285a2efde36b1d62c00b3be81cc93df7d1e6e94837bCluster A x64 EXE Go loader sample
- sha2567720e83c02a027d70ae201c393c1956aa2fa8199879a3a4c4fd1d20b03022cfdCluster B x64 DLL fake MpClient.dll sideload loader sample
- sha25677469615c5f548063922b469a8c0a4116511395d013e5a798e123e9c119acc4bVariant B loader sample
- sha2567828e17e674507ab13dfd84b31b361fa19b9cb27ee130620ba9211feef746d31Variant B loader sample
- sha2567e49da0ae2f81e14841f356b4d69f0480c2d9ce3fab5a3fa91b0036d9a36fa0fCluster B x64 DLL fake MpClient.dll sideload loader sample
- sha2567ed4a256e1d281cb4f194d13ff554fd4fb280dafde0a67a18115ea038ea6c87dVidar core payload (Cluster D) containing in-memory AMSI bypass that patches AmsiScanBuffer; also contains XOR-encrypted XMRig config blobs
- sha2568b40cc7d173efd27fb60f3d260acef28f58d67d1f39597e1d611db311a305f62Cluster A x64 EXE Go loader sample
- sha2568dbcde2a28a0b3de201214d7e3bd43acc97561924daa247c05c4b0536d42be85Variant B loader sample
- sha256901a43b42f997710147295a0625e20c935207f8c531daf5311449ec119a37dccVariant B loader sample
- sha256914c18a04a2727bba9cecab78a1d516ec3c7a3f667e0e5a6081aa0e9206a69feCluster C x86 EXE Go loader sample (shared with Lumma Stealer campaign)
- sha25694db6fa14b4e487dffba709b87e8a7e25483300ed409de243b19fff7cf2f0978Variant B loader sample
- sha25695cd48130247525d8a7e966bd3fa07e9d6c39ebbe3058ecccb336f66bb8e3d1eVariant B loader sample
- sha2569656d3301f63ef6114289739a1c44082206298f787238fc6c190ad87eab24751Cluster A x64 EXE Go loader sample
- sha25696bb418128deeb2b9d2e4b66b98cae07b238b326b6456cc9b86802e67c504a03Variant B loader sample
- sha25698cce1e69873de25e5139aa848f469bef2af345a8a49d15000b5b5e72b582896Variant B loader sample
- sha2569b3df1b6c1b98c201de09a7719066f7bcae6b66a3173b703a617f53fddf67d51Cluster A x64 EXE Go loader sample
- sha256a1039de7ec690d64db9d7d91f3d777d308e49e958de4154aa0b62ded7820f1feVariant B loader sample
- sha256a17a972a05afe387ed32aa2986d5be8bca2f22619d0aedfa834c6963abfab3bfCluster A x64 EXE Go loader sample
- sha256a4f979b4a5d7bc8bc455dd4c09b44e51a389576fccce35a2c8da3ce680237565Cluster A x64 EXE Go loader sample
- sha256a64843ebfbc39e96ec7613003b1b5c3a9b878874ea15a05e1d34ce91781ebfb6Cluster A x64 EXE Go loader sample
- sha256a785fc61fc4ff7cff0ddb540bf7ff12111ed0d6031f78f48387a6c16cb3c5451Variant B loader sample
- sha256aa0083f662f055e8d911c5de3a8f3a31b3c84cacc7dccc30c98f2be14dba4102Variant B loader sample
- sha256aaa2bc1128d8b8b2da76262bf87ede19bac053cca6576efba6aaa71c9438c304Cluster A x64 EXE Go loader sample
- sha256b58814fb3ce5a085014ee6e8d89f7cc1380b234b97170fd5f3398031281c6a77Variant B loader sample
- sha256b6912c23cccc4b0964d55608916297f6978f0b38c80a4beac472004a786fcef7Variant B loader sample
- sha256b830f043076a12748b6a2dc0810ece85439ee77434d991ae7d84201b09ead756Cluster A x64 EXE Go loader sample
- sha256b8b5f6991a3a61083461d5269245bebf28b90934c328848ba8c1e084a5a6216cCluster B x64 DLL fake MpClient.dll sideload loader sample
- sha256b927d265fa29e471c1ae0d31516e480c09c0fb17f480ad08ea8d5b73e84b7a1bCluster B x64 DLL fake MpClient.dll sideload loader sample
- sha256b9b6893fa6b04ee8daa29e515c08239ac5204af1a1fa2bc10006eede1b41329bCluster B x64 DLL fake MpClient.dll sideload loader sample
- sha256bb30cc2b302d9a6963109b201b78d4163bb6c2d7bc8bf5a66e9a744b62fc2717Cluster A x64 EXE Go loader sample
- sha256bd3230e4ceaf32ad2248ab069b164bd2144401967ac69de0a4cd1734fe429d9cVariant B loader sample
- sha256c328b78c21060e2203ac517833fce41572b91878e187f85fa434cd6914659834Cluster A x64 EXE Go loader sample
- sha256c39fedb662259bd76b11616966c41ff1fbda58d9b129b9c1bd818700eea92b29Variant B loader sample
- sha256c7a4a547eb7f6b0b4b75bb6dd8955244bb2618ba234ae740cdedd7c2d30e3465Cluster A x64 EXE Go loader sample
- sha256c7c37a973b14edd5b6b2da4a1497c593e43640735ff54aecc9a3288fa5e548e3Cluster B x64 DLL fake MpClient.dll sideload loader sample
- sha256ca8a00c9d36c64e5dcf562c7ae2b8df4bd6455fe0b41b32ee3a2a528ddc2d155Variant B loader sample
- sha256ce379de03e35e0ea2c88744c29b9e2678165214065f9b957177002c6bbe69084Variant B loader sample
- sha256d18369be4487d7cd0e4bd3dd0da720672e56e13ca43627305e26767e26925551Variant B loader sample
- sha256d2148a458da46e81702136aa915312d360805f083d1f37ff5531db9fbdb8ad6dCluster B x64 DLL fake MpClient.dll sideload loader sample
- sha256d384c403c084967d8c967501ee6332b050af04ef424f13a3f5a88d155389d98cCluster A x64 EXE Go loader sample
- sha256d6446f2803444bd2200d48a01a9ad7d487e67e8e831c9cd13f89cbfec17fd4e2Cluster A x64 EXE Go loader sample
- sha256d7745513034af14617436ad6b3fc125fd0343218411d0c79bda56b0dadc86b2bVariant B loader sample
- sha256d78082dc33c6dca98316e865efa9829c6eb5a97c2ca3cd4ea6c2123a5f6ae45bCluster C x86 EXE Go loader sample (shared with Lumma Stealer campaign)
- sha256d7b56818c829960b692de9ad5a14e52669d953e9f074f7218c3fe34ede4a11a0Cluster B x64 DLL fake MpClient.dll sideload loader sample
- sha256d7c9c9469c513c05aa431fae34f414f91fcf3f794d3e76b6e4d0b92c4cd3ff2eCluster A x64 EXE Go loader sample
- sha256d8ac0c08e4c698017558e532974cf749135d3d49757f05001e6127dc6e07cf17Variant B loader sample
- sha256d8c1f96107a3349e62b3ab9afc60f62af9c89b6961b637a26b71e1230f2b3b8aCluster A x64 EXE Go loader sample
- sha256db2a872f712fbdb1e347d06e29a9ed8278d86710ffc14ff04422be76e47124f4Cluster B x64 DLL fake MpClient.dll sideload loader sample
- sha256dccf9f008b42a04f7e69d3bbf7b5ce81e71308545d6176cc4763920a424e5ac1Variant B loader sample
- sha256e5341edb7c039c456d46c39f194be86ce4b41725d7ad12d297d18aa99cddd675Variant B loader sample
- sha256e88c41a6f769cd760e323b4f7c01835433cd4059cd59630cb1a9eb1181b350edVariant B loader sample
- sha256e9e5e748ec5c0b811c8e60b0e55059edb4d2df86ff3ca45969e57d5fecb11a38Cluster B x64 DLL fake MpClient.dll sideload loader sample
- sha256f0dcb7e407de85d8de8e2221df8dddecac8aec88af8975c9f07e14100f6edb88Cluster A x64 EXE Go loader sample
- sha256f13f9cef5cc020bf673c7f4e19c93c312a043867f46796a8f01927a9a14c2533Variant B loader sample
- sha256f760bc16a585325ba9d74917f9e0994d3a4164c1141158c799b619d2c823e818Variant B loader sample
Detection / Hunteropenrouter
What Happened
Cybercriminals are tricking people into downloading what appear to be cracked versions of popular software through online ads. The downloaded files contain two types of malicious software: one steals saved passwords, browser cookies, and cryptocurrency wallet data, while the other secretly uses the victim's computer to mine cryptocurrency for the attackers. The criminals make their malicious files look legitimate by faking digital signatures from real companies like JustWatch and Bleacher Report, and they make the files artificially large (up to 491 MB) so that automated security tools skip them. Consumers and small businesses in the US and EU are the primary targets. This matters because victims can lose sensitive accounts and money while their computers slow down from hidden mining activity. People should avoid downloading cracked software, ensure their security tools scan files of all sizes, and block the known malicious server addresses listed in the report.
Key Takeaways
- Vidar stealer and XMRig miner co-delivered via malvertising using fake software crack downloads in password-protected .bin archives
- Factory-v3 Go loader framework generates per-build unique binaries with 27 unique build UUIDs across 43 samples, defeating hash-based detection
- All loader samples signed with fabricated Authenticode certificates impersonating JustWatch GmbH and later Bleacher Report; certificates are self-signed and not chained to a trusted root
- File-size inflation up to 491 MB with null byte padding evades sandbox detonation; real malicious content is only 2.3 MB
- In-memory AMSI bypass patches AmsiScanBuffer to return E_INVALIDARG before stealer logic executes; AMSI-related strings XOR-obfuscated with key 0x05
Affected Systems
- Windows x64 and x86 endpoints
- Consumer and small-to-medium business systems
- Systems with Windows Defender (targeted for DLL sideloading via fake MpClient.dll)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Malvertising lures victims to download password-protected .bin archives disguised as cracked software
- Execution: Factory-v3 Go loader (signed with fake Authenticode certificate, inflated up to 491 MB) executes and drops Vidar stealer and XMRig payloads
- Defense Evasion: AMSI bypass patches AmsiScanBuffer to return E_INVALIDARG; DLL sideloading via fake MpClient.dll; null byte padding evades sandbox size limits; XOR-obfuscated strings evade static scanning
- Persistence: Three parallel mechanisms — Registry Run key (SystemAgentService), scheduled task (onlogon trigger), and startup batch script — all point to NisSrv.exe copy in %AppData%
- C2 & Exfiltration: Vidar stealer exfiltrates browser credentials, cookies, and crypto wallets to C2 at 136.243.203.109:443; geolocation beacon sent to ip-api.com/json and embedded in Telegram notification
- Impact: XMRig mines Monero via pool.supportxmr.com with per-victim HWID tracking; operator receives Telegram notifications labeled 'X3D MINER • NEW LOG'
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article does not include any detection rules (YARA, Sigma, Snort/Suricata, KQL, SPL, or EQL). It references Palo Alto Networks product protections (Cortex XDR, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, Prisma Browser) and an external Abuse.ch SSL blocklist for the C2 certificate SHA1 fingerprint, but no rule content is provided.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR can detect dropped executables in %TEMP% and %AppData%, registry Run key modifications, scheduled task creation, and process execution from non-standard paths. However, the AMSI bypass may blind AMSI-dependent detections, and per-build unique hashes with reduced DLL imports (kernel32.dll only) limit hash and import-based detection. |
| Network Visibility | High | C2 IP addresses and the XMRig mining pool domain are explicitly identified. The geolocation beacon to ip-api.com/json and Telegram dead-drop communications provide additional network indicators. NGFW and DNS security can block and alert on these destinations. |
| Detection Difficulty | Moderate | IOCs are well-documented with clear C2 IPs, file paths, and persistence mechanisms. However, per-build unique hashes defeat static hash-based detection, file-size inflation evades sandbox detonation, XOR-obfuscated strings evade static string scanning, and the AMSI bypass may disable script-based detections. Behavioral detections focusing on DLL sideloading, non-standard process paths, and network connections to known C2 provide the best detection opportunities. |
Required Log Sources
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 3 (Network Connection)
- Sysmon Event ID 7 (Image Loaded — for DLL sideloading detection)
- Sysmon Event ID 11 (File Creation — for dropped payloads)
- Sysmon Event ID 13 (Registry Value Set — for Run key persistence)
- Windows Security Event ID 4688 (Process Creation)
- Windows Task Scheduler logs (scheduled task creation)
- DNS query logs
- Proxy/NGFW logs for outbound C2 and mining pool connections
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for MpClient.dll being loaded from non-standard directories (e.g., %AppData%, %TEMP%) rather than the legitimate System32 path, which would indicate DLL search-order hijacking. | Sysmon Event ID 7 (Image Loaded) with ImageLoaded path filtering; EDR module load telemetry | Defense Evasion / Execution | Low — legitimate MpClient.dll loads from System32 only; any other path is highly suspicious |
| Consider hunting for executable files larger than 100 MB that compress to a fraction of their size, which may indicate null byte padding used to evade sandbox size limits. | EDR file size metadata; SIEM correlation between file size on disk and compressed size or entropy analysis | Defense Evasion | Medium — legitimate large installers or game files may trigger; correlate with execution context and signing certificate status |
| Consider hunting for processes that load amsi.dll and subsequently patch the AmsiScanBuffer function in memory, which would indicate an in-memory AMSI bypass attempt. | EDR memory scanning telemetry; Sysmon Event ID 8 (CreateRemoteThread) or Event ID 10 (ProcessAccess) targeting amsi.dll memory regions | Defense Evasion | Low — legitimate applications do not patch AmsiScanBuffer; security tools that perform AMSI integration do not modify the function |
| Consider hunting for NisSrv.exe executing from %AppData%\Roaming\Microsoft\Windows\Temp or any path other than C:\Windows\System32, which would indicate a persistence binary masquerading as the Windows Defender Network Inspection Service. | Sysmon Event ID 1 (Process Creation) with Image path filtering; EDR process execution telemetry | Persistence | Low — the legitimate NisSrv.exe only executes from System32 |
| Consider hunting for outbound connections to known cryptocurrency mining pool domains or stratum protocol traffic on non-standard ports, which may indicate XMRig or similar miners operating in the environment. | NGFW logs, DNS query logs, proxy logs; network flow analysis for stratum protocol patterns | Impact | Medium — legitimate cryptocurrency mining may occur in some environments; correlate with process context and user activity |
Control Gaps
- Sandbox solutions with file-size limits of 50-100 MB will silently skip inflated loader binaries and fail to detonate them
- Hash-based detection is defeated by per-build unique binaries with 27 unique build UUIDs across 43 samples
- Static string scanning is evaded by XOR-obfuscated AMSI strings and 32-byte rotating XOR encryption of config blobs
- Authenticode validation alone may not flag binaries if users are conditioned to bypass SmartScreen warnings for unrecognized publishers
- AMSI-dependent script and code scanning is disabled after the in-memory patch is applied
Key Behavioral Indicators
- MpClient.dll loaded from any path other than C:\Windows\System32 (DLL sideloading via T1574.002)
- NisSrv.exe executing from %AppData%\Roaming\Microsoft\Windows\Temp (masquerading as Windows Defender component)
- Registry Run key value named 'SystemAgentService' under HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Scheduled task named 'SystemAgentService' with onlogon trigger
- PE files with zeroed TimeDateStamp, no version info, and imports limited to kernel32.dll only
- Go build metadata referencing Factory-v3 / UpdateFactory builder with Go version 1.25.9
- Executable files larger than 100 MB with low entropy trailing sections (null byte padding)
- Authenticode signatures with subject CN=justwatch.com or CN=*.bleacherreport.com that do not chain to a trusted root CA
- Process creating files named MicrosoftUpdate.exe, MicrosoftEdgeUpdate.exe, or mgwthmc2.dat in %TEMP% or %AppData%\Roaming\Microsoft\Windows\Temp
False Positive Assessment
Low — The IOCs are highly specific (C2 IPs, unique filenames like FEbJCNWOCKMJ.bat and mgwthmc2.dat, fake certificate subjects, and non-standard execution paths). Behavioral detections for MpClient.dll sideloading and NisSrv.exe from %AppData% have minimal false positive risk. Mining pool domain blocking may produce false positives if legitimate mining is permitted in the environment.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking outbound connections to C2 IPs 136.243.203.109, 116.203.243.208, 136.243.203.111, and 138.199.246.13, and the mining pool domain pool.supportxmr.com at your firewall and DNS security layers.
- If your EDR supports host isolation, consider isolating any endpoints observed communicating with the listed C2 IPs or executing NisSrv.exe from non-standard paths.
- Consider searching endpoint telemetry for the persistence indicators — Registry Run key value 'SystemAgentService', scheduled task 'SystemAgentService', and startup batch script FEbJCNWOCKMJ.bat — to identify compromised hosts.
- If applicable, consider adding the fake certificate serial number 2f:7e:f0:15:7d:17:62:5c:09:86:91:ce:f1:ff:7d:63 to your certificate blocklist or application control deny rules.
Infrastructure Hardening
- Consider configuring security tooling and sandboxes to strip null byte padding before applying file-size limits, so that inflated binaries are still analyzed.
- Evaluate whether your email gateway and web filter can scan password-protected .bin archives; if not, consider blocking or quarantining .bin attachments from untrusted sources.
- Consider enforcing strict Authenticode chain validation that rejects certificates not chained to a Microsoft-trusted root CA, and consider blocklisting known rogue certificate serial numbers.
- If supported by your DNS security solution, consider adding alerts for DNS queries to pool.supportxmr.com and other known XMRig mining pool domains.
User Protection
- Consider deploying browser security extensions or Prisma Browser-equivalent solutions that dynamically scan web pages to block malvertising redirects.
- If your EDR supports it, consider enabling behavioral threat protection rules that alert on DLL sideloading of MpClient.dll from non-standard paths.
- Evaluate whether your AMSI-integrated security tools can detect or alert on AmsiScanBuffer patching attempts in memory.
- Consider ensuring endpoint security agents are configured to scan files regardless of size, with padding-stripping or entropy analysis for oversized files.
Security Awareness
- Consider reinforcing awareness training about the risks of downloading cracked or pirated software, which is the primary initial access vector for this campaign.
- Consider educating users about ignoring SmartScreen or Authenticode warnings that reference recognizable brand names like JustWatch or Bleacher Report on downloaded executables.
- If applicable to your organization, consider reminding users that legitimate software updates do not arrive as password-protected .bin archives from web searches.
MITRE ATT&CK Mapping
Execution
Persistence
Stealth
Defense Impairment
Credential Access
Collection
Command and Control
Impact
Additional IOCs
- File Hashes:
ab92f731ab20774dfdb95664ee41a2fbafe2a284(SHA1) - SSL certificate SHA1 fingerprint of Vidar C2 server 136.243.203.109; listed on Abuse.ch SSL blocklistd42595b695fc008ef2c56aabd8efd68e(MD5) - Imphash for Cluster A x64 EXE Go loaders (26 samples)d8b31f8c03e0c76ff245ed05a15ffe6c(MD5) - Imphash for Cluster B x64 DLL fake MpClient.dll sideload loaders (13 samples)1aae8bf580c846f39c71c05898e57e88(MD5) - Imphash for Cluster C x86 EXE Go loaders (3 samples, shared with Lumma Stealer campaign)c10333c92889b65c3590ef2b3819b420(MD5) - Imphash for Cluster D Vidar core payload (1 sample)097a87cfa4a5186aba3bba096866692951bde59c6f0c2e8c1c4a599246d14da8(SHA256) - Cluster A x64 EXE Go loader sample201594c9d173bba6cb509407ecba378c19b93da0a81a2182a913c480e6dbb54e(SHA256) - Cluster A x64 EXE Go loader sample20bf39e1e67152039e70a01ad9e7b23c08d23d2a724ef9c44903f3d4353a2275(SHA256) - Cluster A x64 EXE Go loader sample35dde1b2482b12582820a861e7c46f10721af6b75052fc872c05d2230a4e8ca1(SHA256) - Cluster A x64 EXE Go loader sample43920ef7d2742d140a1ab2a1ef172c716903474c73561377dc4f1534d2c5f581(SHA256) - Cluster A x64 EXE Go loader sample47d6d1a38534ba897a5a1e293e3d5df303bbd8e0526e756ad08887ffc1417bef(SHA256) - Cluster A x64 EXE Go loader sample68ced9d7c1b1ff8ffb5f56c7d3f849d4fd16a1b95324426811424b40043d6d25(SHA256) - Cluster A x64 EXE Go loader sample6b7ff061eebeb9ead8812c410247768a7ba90786aeeb1bafa6412cc5b08237b5(SHA256) - Cluster A x64 EXE Go loader sample739cdedb20de39aeb1f15dc8c2dbbf15fa993250fd879bf87443ff9aeaf4997b(SHA256) - Cluster A x64 EXE Go loader sample74df77b6a83d89fa137fd285a2efde36b1d62c00b3be81cc93df7d1e6e94837b(SHA256) - Cluster A x64 EXE Go loader sample8b40cc7d173efd27fb60f3d260acef28f58d67d1f39597e1d611db311a305f62(SHA256) - Cluster A x64 EXE Go loader sample9656d3301f63ef6114289739a1c44082206298f787238fc6c190ad87eab24751(SHA256) - Cluster A x64 EXE Go loader sample9b3df1b6c1b98c201de09a7719066f7bcae6b66a3173b703a617f53fddf67d51(SHA256) - Cluster A x64 EXE Go loader samplea17a972a05afe387ed32aa2986d5be8bca2f22619d0aedfa834c6963abfab3bf(SHA256) - Cluster A x64 EXE Go loader samplea4f979b4a5d7bc8bc455dd4c09b44e51a389576fccce35a2c8da3ce680237565(SHA256) - Cluster A x64 EXE Go loader samplea64843ebfbc39e96ec7613003b1b5c3a9b878874ea15a05e1d34ce91781ebfb6(SHA256) - Cluster A x64 EXE Go loader sampleaaa2bc1128d8b8b2da76262bf87ede19bac053cca6576efba6aaa71c9438c304(SHA256) - Cluster A x64 EXE Go loader sampleb830f043076a12748b6a2dc0810ece85439ee77434d991ae7d84201b09ead756(SHA256) - Cluster A x64 EXE Go loader samplebb30cc2b302d9a6963109b201b78d4163bb6c2d7bc8bf5a66e9a744b62fc2717(SHA256) - Cluster A x64 EXE Go loader samplec328b78c21060e2203ac517833fce41572b91878e187f85fa434cd6914659834(SHA256) - Cluster A x64 EXE Go loader samplec7a4a547eb7f6b0b4b75bb6dd8955244bb2618ba234ae740cdedd7c2d30e3465(SHA256) - Cluster A x64 EXE Go loader sampled384c403c084967d8c967501ee6332b050af04ef424f13a3f5a88d155389d98c(SHA256) - Cluster A x64 EXE Go loader sampled6446f2803444bd2200d48a01a9ad7d487e67e8e831c9cd13f89cbfec17fd4e2(SHA256) - Cluster A x64 EXE Go loader sampled7c9c9469c513c05aa431fae34f414f91fcf3f794d3e76b6e4d0b92c4cd3ff2e(SHA256) - Cluster A x64 EXE Go loader sampled8c1f96107a3349e62b3ab9afc60f62af9c89b6961b637a26b71e1230f2b3b8a(SHA256) - Cluster A x64 EXE Go loader samplef0dcb7e407de85d8de8e2221df8dddecac8aec88af8975c9f07e14100f6edb88(SHA256) - Cluster A x64 EXE Go loader sample0a6a67a2fc4d79ec1cd8afc5b8b7a5e69a406e53d57a7334e097c5d0644de5f6(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sample488d941b7b4428b0f4a0e5495e3857b9b96215fb3e7f164b06640d59096425e6(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sample5d7324d8b5a25f862ef8223c6766d0e80af3ad168e17312b265e13a3a68e0ded(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sample7720e83c02a027d70ae201c393c1956aa2fa8199879a3a4c4fd1d20b03022cfd(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sample7e49da0ae2f81e14841f356b4d69f0480c2d9ce3fab5a3fa91b0036d9a36fa0f(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sampleb8b5f6991a3a61083461d5269245bebf28b90934c328848ba8c1e084a5a6216c(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sampleb927d265fa29e471c1ae0d31516e480c09c0fb17f480ad08ea8d5b73e84b7a1b(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sampleb9b6893fa6b04ee8daa29e515c08239ac5204af1a1fa2bc10006eede1b41329b(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader samplec7c37a973b14edd5b6b2da4a1497c593e43640735ff54aecc9a3288fa5e548e3(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sampled2148a458da46e81702136aa915312d360805f083d1f37ff5531db9fbdb8ad6d(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sampled7b56818c829960b692de9ad5a14e52669d953e9f074f7218c3fe34ede4a11a0(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sampledb2a872f712fbdb1e347d06e29a9ed8278d86710ffc14ff04422be76e47124f4(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader samplee9e5e748ec5c0b811c8e60b0e55059edb4d2df86ff3ca45969e57d5fecb11a38(SHA256) - Cluster B x64 DLL fake MpClient.dll sideload loader sample03e6f4f49cec3af38bbec9ed64c195c7a85a630ec989efb3669f04a2993c1dd7(SHA256) - Cluster C x86 EXE Go loader sample (shared with Lumma Stealer campaign)914c18a04a2727bba9cecab78a1d516ec3c7a3f667e0e5a6081aa0e9206a69fe(SHA256) - Cluster C x86 EXE Go loader sample (shared with Lumma Stealer campaign)d78082dc33c6dca98316e865efa9829c6eb5a97c2ca3cd4ea6c2123a5f6ae45b(SHA256) - Cluster C x86 EXE Go loader sample (shared with Lumma Stealer campaign)15489bcd6e4602b41c9a787ec8d7ab027d5e45d400938048bb1c702ad5937980(SHA256) - Variant B loader sample (Bleacher Report certificate impersonation)169a330353e53a409e0109c914404354741ff1e1c64e501738dc05e58ea92abc(SHA256) - Variant B loader sample2a02ec4af5ed591afdf1236a443e3b68642ee133f38a2857d1eada51246ab498(SHA256) - Variant B loader sample2b7297a5f502a2e9a59066f0a370bc5a8b28addd0e27975db3d770f801c15397(SHA256) - Variant B loader sample2c0b344af415b787b396c8e23bbeb112bd471a1ca1d12cf357c48e2ee1ae068c(SHA256) - Variant B loader sample2c6e8f86c05781af12b323311e83e011f1a603928e2086c48e2ca59e33d90dbe(SHA256) - Variant B loader sample2e11a16f94484e0f43eb4572f800f26f0b4a1314cbdae3c44c1ae35f376906d8(SHA256) - Variant B loader sample2f1400a91c853d61622f4d21ed97d96ea1093c0fa1586669bea6f6baa331251f(SHA256) - Variant B loader sample314ce675c040c63b825f213965f5c76a3bd09bf70e138708367e2a84e9e84b30(SHA256) - Variant B loader sample32172e4d8d2ab9fb29b36c9b279117be6ff611b5b91ff7b1c42501a5ec969f2b(SHA256) - Variant B loader sample330efeebba3782994612fdfe20ff96c930af33a83b88a342b6622461511921b2(SHA256) - Variant B loader sample35b51bbe42edd15918b015eaa1b4f0e6b5c94f186d71d887e39f1da69a4dec3f(SHA256) - Variant B loader sample3c3f12531045b7eedfe25e0f291d4792b0d8c8366f8de043e2fa8ecf34ccb913(SHA256) - Variant B loader sample3db33b0423bb9278db267a7adb036ecbd6aeebd7909d06d824919708b1e12e1b(SHA256) - Variant B loader sample3e906ae47e9836a591f44d4b743e961d634a404fa8fd8bfae64f1d54c853be2b(SHA256) - Variant B loader sample4bf770a59d367b532dec32668f86003b17d93918dba5ef5fd2b19c5394252436(SHA256) - Variant B loader sample4f456142caf590d98fb11ca247800bb417766714527e5a4707ac2f5d01542626(SHA256) - Variant B loader sample53d263b292be387843fadb7131c2d538b4262c81f5b95cfacafacf2d5446c06e(SHA256) - Variant B loader sample5494909e0f5221db75e933b28981b2d0e118f227b7d8a5980d88b500b76dfc2e(SHA256) - Variant B loader sample54dc05ab56244444f86d69b8274a6075906f7ba2307b08e08d3884abde255495(SHA256) - Variant B loader sample559f46ceb801a3540eace594476718e1486b5b4423cfb4ff64530ff8fb4a3815(SHA256) - Variant B loader sample5838ae6c748dcbdfa13c6529c654cb821897d29835d3e7e05ca23fb2f3794f02(SHA256) - Variant B loader sample59b9153c4e9e155c976db1a2fd4d1b28fa10bb9c4dcafdc4758b352c037e3d86(SHA256) - Variant B loader sample5b6a466b65d479b77a03b15a95ac097b45e23ff7ae5ef6282985b2a503deb691(SHA256) - Variant B loader sample613e5314a7ded3155cdec49fd34e852e181f4651d78bd8bf3adad2f4dbf22b0d(SHA256) - Variant B loader sample62877a5096828c4bc2fca7cbee7d38b11a0c90fd0d3fc8c37981581e9988c919(SHA256) - Variant B loader sample634e89d8592d7c9e2bc1c098217a813947b44a4f80bc569e9a15c1e8b0864b91(SHA256) - Variant B loader sample67569adec99fd38b114ae07e2e549e6c16f75368f3c5373022c84934ed1c8e84(SHA256) - Variant B loader sample6d49233b1fca22f3823e856e4c16749e9c45f384ea57055fead16df35b217226(SHA256) - Variant B loader sample71c79e8bf71ed257435ea9b8b91e118ba03ec681860651190f7d7457804313ee(SHA256) - Variant B loader sample77469615c5f548063922b469a8c0a4116511395d013e5a798e123e9c119acc4b(SHA256) - Variant B loader sample7828e17e674507ab13dfd84b31b361fa19b9cb27ee130620ba9211feef746d31(SHA256) - Variant B loader sample8dbcde2a28a0b3de201214d7e3bd43acc97561924daa247c05c4b0536d42be85(SHA256) - Variant B loader sample901a43b42f997710147295a0625e20c935207f8c531daf5311449ec119a37dcc(SHA256) - Variant B loader sample94db6fa14b4e487dffba709b87e8a7e25483300ed409de243b19fff7cf2f0978(SHA256) - Variant B loader sample95cd48130247525d8a7e966bd3fa07e9d6c39ebbe3058ecccb336f66bb8e3d1e(SHA256) - Variant B loader sample96bb418128deeb2b9d2e4b66b98cae07b238b326b6456cc9b86802e67c504a03(SHA256) - Variant B loader sample98cce1e69873de25e5139aa848f469bef2af345a8a49d15000b5b5e72b582896(SHA256) - Variant B loader samplea1039de7ec690d64db9d7d91f3d777d308e49e958de4154aa0b62ded7820f1fe(SHA256) - Variant B loader samplea785fc61fc4ff7cff0ddb540bf7ff12111ed0d6031f78f48387a6c16cb3c5451(SHA256) - Variant B loader sampleaa0083f662f055e8d911c5de3a8f3a31b3c84cacc7dccc30c98f2be14dba4102(SHA256) - Variant B loader sampleb58814fb3ce5a085014ee6e8d89f7cc1380b234b97170fd5f3398031281c6a77(SHA256) - Variant B loader sampleb6912c23cccc4b0964d55608916297f6978f0b38c80a4beac472004a786fcef7(SHA256) - Variant B loader samplebd3230e4ceaf32ad2248ab069b164bd2144401967ac69de0a4cd1734fe429d9c(SHA256) - Variant B loader samplec25799facb3e788830bcf614f33411d3bcfc0edd4a220e160b5eb4ce700039f(SHA256) - Variant B loader samplec39fedb662259bd76b11616966c41ff1fbda58d9b129b9c1bd818700eea92b29(SHA256) - Variant B loader sampleca8a00c9d36c64e5dcf562c7ae2b8df4bd6455fe0b41b32ee3a2a528ddc2d155(SHA256) - Variant B loader samplece379de03e35e0ea2c88744c29b9e2678165214065f9b957177002c6bbe69084(SHA256) - Variant B loader sampled18369be4487d7cd0e4bd3dd0da720672e56e13ca43627305e26767e26925551(SHA256) - Variant B loader sampled7745513034af14617436ad6b3fc125fd0343218411d0c79bda56b0dadc86b2b(SHA256) - Variant B loader sampled8ac0c08e4c698017558e532974cf749135d3d49757f05001e6127dc6e07cf17(SHA256) - Variant B loader sampledccf9f008b42a04f7e69d3bbf7b5ce81e71308545d6176cc4763920a424e5ac1(SHA256) - Variant B loader samplee5341edb7c039c456d46c39f194be86ce4b41725d7ad12d297d18aa99cddd675(SHA256) - Variant B loader samplee88c41a6f769cd760e323b4f7c01835433cd4059cd59630cb1a9eb1181b350ed(SHA256) - Variant B loader samplef13f9cef5cc020bf673c7f4e19c93c312a043867f46796a8f01927a9a14c2533(SHA256) - Variant B loader samplef760bc16a585325ba9d74917f9e0994d3a4164c1141158c799b619d2c823e818(SHA256) - Variant B loader sample
- Registry Keys:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run- Registry Run key used for persistence; value name 'SystemAgentService' with data pointing to NisSrv.exe -s in %AppData%\Roaming\Microsoft\Windows\Temp
- File Paths:
%TEMP%\MicrosoftUpdate.exe- Vidar stealer component dropped and executed from TEMP directory%AppData%\Roaming\Microsoft\Windows\Temp\MicrosoftEdgeUpdate.exe- XMRig launcher dropped by malware; launched with --config=mgwthmc2.dat%AppData%\Roaming\Microsoft\Windows\Temp\NisSrv.exe- Persistence copy of loader; filename mimics Windows Defender Network Inspection Service binary%AppData%\Roaming\Microsoft\Windows\Temp\libuv-1.dll- XMRig dependency DLL dropped alongside miner%AppData%\Roaming\Microsoft\Windows\Temp\WinRing0x64.sys- XMRig kernel driver dropped for hardware access during mining%AppData%\Roaming\Microsoft\Windows\Temp\mgwthmc2.dat- XMRig Monero configuration file with encrypted wallet address and pool detailsC:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\FEbJCNWOCKMJ.bat- Startup batch script for persistence; launches NisSrv.exe on user logonC:\Users\Administrator\Desktop\UpdateFactory\compiler\1.25.9\go\src\runtime\cgo- PDB path embedded in loader DLLs revealing Factory-v3 builder internal name 'UpdateFactory' and Go version 1.25.9
- Command Lines:
- Purpose: Create scheduled task for persistence on user logon | Tools:
schtasks.exe| Stage: Persistence |schtasks /create /tn "SystemAgentService" /tr "NisSrv.exe -s" /sc onlogon /f
- Purpose: Create scheduled task for persistence on user logon | Tools:
- Other:
ci0iiif- Telegram channel used as dead-drop for Variant B C2 notifications; operator receives 'X3D MINER • NEW LOG' messages for each new victim infection2f:7e:f0:15:7d:17:62:5c:09:86:91:ce:f1:ff:7d:63- Serial number of fake Authenticode certificate impersonating JustWatch GmbH; certificate is self-signed by rogue CA 'WR3' and not trusted by any public trust storeCN=justwatch.com- Fake Authenticode certificate subject common name impersonating JustWatch GmbH; used to sign all 43 original loader samplesCN=*.bleacherreport.com- Fake Authenticode certificate subject common name impersonating Bleacher Report; used to sign 56 Variant B loader samples