Fake Game Cheats on GitHub and Reddit Deliver Vidar Stealer 2.0

Cybersecurity researchers have uncovered several malware campaigns targeting gamers who search for free game cheats online.

The attacks distribute Vidar Stealer 2.0, a powerful information-stealing malware, through fake cheat tools promoted on platforms such as GitHub and Reddit.

The campaigns specifically target players of popular competitive games like Counter-Strike, Valorant, Fortnite, and Call of Duty.

Attackers exploit the demand for cheats that provide unfair advantages, such as aimbots, wallhacks, and triggerbots. By promising free cheat tools, cybercriminals lure victims into downloading malicious files that ultimately steal sensitive information from their systems.

Security researchers discovered hundreds of GitHub pages and repositories hosting links to fake cheat software.

Many of these pages appear legitimate at first glance and often include instructions on installing the cheats. In some cases, the repositories only host a landing page and redirect users to external download sites controlled by attackers.

Fake Cheat Tools Used As Malware Delivery

The attack usually begins with posts on Reddit communities, Discord channels, or gaming forums where users share links to “free” cheat tools. Victims who click the links are directed to GitHub pages or websites that host the malicious downloads.

The files are often disguised with names such as TempSpoofer.exe, Monotone.exe, or CFXBypass.exe, which appear to be tools designed to bypass game bans or hardware identification systems.

Reddit posts mentioning and promoting the game cheat for CS2. This leads to a fake website that will download and install the infostealer (Source: acronis)
Reddit posts mentioning and promoting the game cheat for CS2. This leads to a fake website that will download and install the infostealer (Source: acronis)

However, analysis revealed that these files are actually PowerShell-based loaders compiled into .NET executables.

The loader then contacts a Pastebin link to retrieve a second-stage payload hosted on GitHub. After downloading the file, the malware creates a randomly named directory in the %AppData% folder, hides the files, and executes the final payload.

Example of fake repositories hosted on GitHub that distribute fake game cheat containing infostealer (Source: acronis)
Example of fake repositories hosted on GitHub that distribute fake game cheat containing infostealer (Source: acronis)

Vidar Stealer 2.0 Targets Credentials and Sensitive Data

Vidar Stealer is a well-known information-stealing malware family that has been active since 2018. The newly updated Vidar 2.0 version includes improved performance, multithreading, and stronger anti-analysis capabilities.

Once installed, the malware begins collecting sensitive data from the infected system. It targets browser credentials, cookies, cryptocurrency wallets, FTP and SSH credentials, browser extensions, and local files.

The malware can also capture screenshots and extract tokens from messaging applications such as Discord and Telegram.

Full infection chain starting from fake repository on GitHub, leading to execution of the Vidar 2.0 after the user installs the fake cheat (Source: acronis)
Full infection chain starting from fake repository on GitHub, leading to execution of the Vidar 2.0 after the user installs the fake cheat (Source: acronis)

According to Acronis research, to hide its command-and-control infrastructure, Vidar uses legitimate services such as Telegram bots and Steam profiles as dead-drop resolvers. These services store the real server addresses that the malware uses to send stolen data.

Researchers believe the rise of Vidar campaigns is partly due to recent law enforcement actions that disrupted other popular stealers, such as Lumma and Rhadamanthys.

With those operations weakened, cybercriminals are shifting toward Vidar as an alternative tool for credential theft.

Security experts warn that downloading software from unofficial sources, especially cheat tools, significantly increases the risk of malware infection.

Gamers are advised to avoid downloading cheats and to rely only on trusted platforms and security software to protect their systems.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories