
Gold Evergreen's Vidar Variant Hits Indonesia With Six-Layer Evasion Stack
A heavily packed, unsigned Win32 executable confirmed as a Vidar stealer variant runs a six-stage anti-analysis gauntlet before harvesting browser credentials and cryptocurrency wallet data. The operation uses a dual-channel C2 architecture — Telegram for configuration retrieval and two bare-IP HTTP endpoints sharing the path '/1707' for staging and exfiltration — attributed to Gold Evergreen with a regional focus on Indonesia.
A 1.41-megabyte unsigned Win32 executable, packed to near-maximum entropy and fetched silently through an Internet Explorer cache path, is at the centre of a credential-theft operation targeting Windows users in Indonesia. The payload — confirmed as a Vidar stealer variant by three independent YARA rules and a Zenbox sandbox classification of MALWARE/STEALER/TROJAN/EVADER at 100% confidence — does not simply steal and exfiltrate.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read