Darktrace investigated a July 2026 intrusion in which a user at an EMEA customer downloaded a fake Google Gemini installer that delivered the Vidar information stealer. According to Darktrace, the lure used a Google Colab page that redirected users to a fraudulent download site, while the payload targeted browser credentials. Darktrace reported that its response system quarantined the infected device.
Darktrace investigated a July 2026 intrusion in which a malicious executable impersonating a Google Gemini installer delivered the Vidar information stealer to a customer environment in the Europe, Middle East and Africa region. The incident used Google Colab as part of a deceptive software-download path, according to Darktrace's incident report.
The file was named Download_Google_Gemini_For_Windows.exe. Help Net Security, citing Darktrace's analysis, reports that a search result associated with the suspicious filename led to a Google Colab page, which then redirected users to micronsoftwares[.]com, a site presented as a "Windows Software Hub."
Trusted services in the delivery chain
Google Colab is a legitimate browser-based Jupyter notebook platform used for code execution and machine learning workloads. Darktrace reported that SSL connections to Google Colab immediately preceded execution of the suspicious binary in the affected environment. The researchers described that timing as evidence consistent with a user interacting with the Colab-hosted lure before reaching the download site.
Darktrace could not conclusively reconstruct the full download chain from HTTP or file-download telemetry, according to reporting by GBHackers. At the time of Darktrace's July 15 review, the Colab page remained active and contained the executable, GBHackers reported.
The downloaded ZIP archive included a README file instructing users to run the executable with administrator privileges and add it to antivirus exclusions, according to Help Net Security. Those instructions are established social-engineering techniques that can reduce endpoint defenses before malware execution.
Vidar behavior and containment
Darktrace identified the payload as a newer Go-compiled variant of Vidar, an information stealer. According to Help Net Security, the malware communicated with Telegram-based infrastructure and used dtm[.]kijangturbo88[.]top as a command-and-control endpoint.
Darktrace identified suspicious process activity, anomalous network communications, and indicators of credential theft during the incident. Help Net Security reports that a separate endpoint-protection detection later supported the assessment that the activity targeted browser credentials. Darktrace's Autonomous Response system blocked communications with malicious infrastructure and quarantined the infected device, the firm reported.
The malware itself was not novel, but researchers characterized the AI-themed lure and delivery mechanism as notable. For security teams, the incident illustrates a broader pattern: software acquisition workflows, especially searches for popular AI tools, can become an initial-access path when users encounter convincing branding and legitimate cloud services. Controls that inspect newly downloaded executables, correlate browser or cloud-service activity with process execution, and flag requests to disable endpoint protections can help surface this type of campaign even when the initial hosting service is trusted.
Key Points #
- 1Darktrace traced a Vidar infection to a fake Gemini installer, with Google Colab used in the deceptive download workflow.
- 2The Go-compiled Vidar variant targeted browser credentials and communicated with Telegram-based command-and-control infrastructure, according to Darktrace.
- 3Comparable campaigns make trusted cloud services and AI software searches valuable detection points for download, execution, and network telemetry correlation.
Scoring Rationale #
This is a notable AI-themed malware delivery campaign with direct relevance to organizations deploying or evaluating generative AI tools. It does not disclose a new Vidar capability, but it offers actionable detection context around trusted-host abuse, executable downloads, and credential-theft behavior.
Sources #
Primary source and supporting public references used for this report.
Practice with real Ride-Hailing data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card