< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Vidar infostealer deployed via fake Google Gemini installers

Cybercriminals are using fake Google Gemini installers to distribute the Vidar infostealer, targeting users through deceptive search results and trusted platforms. Researchers from Darktrace identified the campaign, which targeted a company network in the Europe, Middle East, and Africa (EMEA) region.

The attack chain begins when users searching for Gemini-related software are directed to a Google Colab page. This cloud-based platform is used to host a download prompt, providing a veneer of legitimacy before redirecting users to a site masquerading as a ‘Windows Software Hub’. From there, users download a malicious file named ‘Download_Google_Gemini_For_Windows.exe’.

Once executed, the malware—a Go-compiled variant of the Vidar infostealer—attempts to collect sensitive data, including saved browser credentials and passwords. The malware utilizes Telegram-based infrastructure for its command-and-control communications. The campaign highlights a growing trend of attackers leveraging popular AI brands and trusted cloud services to bypass user suspicion and deliver malware.

Entities

Darktrace · Google · Google Colab · Vidar