FILEMembers
FILE

Gold Evergreen's Vidar Variant Hits Indonesia With Six-Layer Evasion Stack

A heavily packed, unsigned Win32 executable confirmed as a Vidar stealer variant runs a six-stage anti-analysis gauntlet before harvesting browser credentials and cryptocurrency wallet data. The operation uses a dual-channel C2 architecture — Telegram for configuration retrieval and two bare-IP HTTP endpoints sharing the path '/1707' for staging and exfiltration — attributed to Gold Evergreen with a regional focus on Indonesia.

May 30, 2026, 23:44 (UTC+9)Last seenMay 30, 2026Severity77ByCTX TeamActorGold EvergreenBusiness ClubIOC5MITRE11RegionsID

A 1.41-megabyte unsigned Win32 executable, packed to near-maximum entropy and fetched silently through an Internet Explorer cache path, is at the centre of a credential-theft operation targeting Windows users in Indonesia. The payload — confirmed as a Vidar stealer variant by three independent YARA rules and a Zenbox sandbox classification of MALWARE/STEALER/TROJAN/EVADER at 100% confidence — does not simply steal and exfiltrate.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence