Cybersecurity researchers have uncovered several malware campaigns targeting gamers who search for free game cheats online.
The attacks distribute Vidar Stealer 2.0, a powerful information-stealing malware, through fake cheat tools promoted on platforms such as GitHub and Reddit.
The campaigns specifically target players of popular competitive games like Counter-Strike, Valorant, Fortnite, and Call of Duty.
Attackers exploit the demand for cheats that provide unfair advantages, such as aimbots, wallhacks, and triggerbots. By promising free cheat tools, cybercriminals lure victims into downloading malicious files that ultimately steal sensitive information from their systems.
Security researchers discovered hundreds of GitHub pages and repositories hosting links to fake cheat software.
Many of these pages appear legitimate at first glance and often include instructions on installing the cheats. In some cases, the repositories only host a landing page and redirect users to external download sites controlled by attackers.
Fake Cheat Tools Used As Malware Delivery
The attack usually begins with posts on Reddit communities, Discord channels, or gaming forums where users share links to “free” cheat tools. Victims who click the links are directed to GitHub pages or websites that host the malicious downloads.
The files are often disguised with names such as TempSpoofer.exe, Monotone.exe, or CFXBypass.exe, which appear to be tools designed to bypass game bans or hardware identification systems.

However, analysis revealed that these files are actually PowerShell-based loaders compiled into .NET executables.
The loader then contacts a Pastebin link to retrieve a second-stage payload hosted on GitHub. After downloading the file, the malware creates a randomly named directory in the %AppData% folder, hides the files, and executes the final payload.

Vidar Stealer 2.0 Targets Credentials and Sensitive Data
Vidar Stealer is a well-known information-stealing malware family that has been active since 2018. The newly updated Vidar 2.0 version includes improved performance, multithreading, and stronger anti-analysis capabilities.
Once installed, the malware begins collecting sensitive data from the infected system. It targets browser credentials, cookies, cryptocurrency wallets, FTP and SSH credentials, browser extensions, and local files.
The malware can also capture screenshots and extract tokens from messaging applications such as Discord and Telegram.

According to Acronis research, to hide its command-and-control infrastructure, Vidar uses legitimate services such as Telegram bots and Steam profiles as dead-drop resolvers. These services store the real server addresses that the malware uses to send stolen data.
Researchers believe the rise of Vidar campaigns is partly due to recent law enforcement actions that disrupted other popular stealers, such as Lumma and Rhadamanthys.
With those operations weakened, cybercriminals are shifting toward Vidar as an alternative tool for credential theft.
Security experts warn that downloading software from unofficial sources, especially cheat tools, significantly increases the risk of malware infection.
Gamers are advised to avoid downloading cheats and to rely only on trusted platforms and security software to protect their systems.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.