cd /news/ai-tools/fake-gemini-installer-delivers-vidar… · home topics ai-tools article
[ARTICLE · art-105657] src=letsdatascience.com ↗ pub= topic=ai-tools verified=true sentiment=· neutral

Fake Gemini Installer Delivers Vidar Credential Stealer

Darktrace investigated a July 2026 intrusion in which a user at an EMEA customer downloaded a fake Google Gemini installer that delivered the Vidar information stealer. The lure used a Google Colab page that redirected users to a fraudulent download site, and the payload targeted browser credentials. Darktrace's Autonomous Response system quarantined the infected device.

read3 min views5 publishedAug 21, 2026
Fake Gemini Installer Delivers Vidar Credential Stealer
Image: Letsdatascience (auto-discovered)

Darktrace investigated a July 2026 intrusion in which a user at an EMEA customer downloaded a fake Google Gemini installer that delivered the Vidar information stealer. According to Darktrace, the lure used a Google Colab page that redirected users to a fraudulent download site, while the payload targeted browser credentials. Darktrace reported that its response system quarantined the infected device.

Darktrace investigated a July 2026 intrusion in which a malicious executable impersonating a Google Gemini installer delivered the Vidar information stealer to a customer environment in the Europe, Middle East and Africa region. The incident used Google Colab as part of a deceptive software-download path, according to Darktrace's incident report.

The file was named Download_Google_Gemini_For_Windows.exe. Help Net Security, citing Darktrace's analysis, reports that a search result associated with the suspicious filename led to a Google Colab page, which then redirected users to micronsoftwares[.]com, a site presented as a "Windows Software Hub."

Trusted services in the delivery chain

Google Colab is a legitimate browser-based Jupyter notebook platform used for code execution and machine learning workloads. Darktrace reported that SSL connections to Google Colab immediately preceded execution of the suspicious binary in the affected environment. The researchers described that timing as evidence consistent with a user interacting with the Colab-hosted lure before reaching the download site.

Darktrace could not conclusively reconstruct the full download chain from HTTP or file-download telemetry, according to reporting by GBHackers. At the time of Darktrace's July 15 review, the Colab page remained active and contained the executable, GBHackers reported.

The downloaded ZIP archive included a README file instructing users to run the executable with administrator privileges and add it to antivirus exclusions, according to Help Net Security. Those instructions are established social-engineering techniques that can reduce endpoint defenses before malware execution.

Vidar behavior and containment

Darktrace identified the payload as a newer Go-compiled variant of Vidar, an information stealer. According to Help Net Security, the malware communicated with Telegram-based infrastructure and used dtm[.]kijangturbo88[.]top as a command-and-control endpoint.

Darktrace identified suspicious process activity, anomalous network communications, and indicators of credential theft during the incident. Help Net Security reports that a separate endpoint-protection detection later supported the assessment that the activity targeted browser credentials. Darktrace's Autonomous Response system blocked communications with malicious infrastructure and quarantined the infected device, the firm reported.

The malware itself was not novel, but researchers characterized the AI-themed lure and delivery mechanism as notable. For security teams, the incident illustrates a broader pattern: software acquisition workflows, especially searches for popular AI tools, can become an initial-access path when users encounter convincing branding and legitimate cloud services. Controls that inspect newly downloaded executables, correlate browser or cloud-service activity with process execution, and flag requests to disable endpoint protections can help surface this type of campaign even when the initial hosting service is trusted.

Key Points #

  • 1Darktrace traced a Vidar infection to a fake Gemini installer, with Google Colab used in the deceptive download workflow.
  • 2The Go-compiled Vidar variant targeted browser credentials and communicated with Telegram-based command-and-control infrastructure, according to Darktrace.
  • 3Comparable campaigns make trusted cloud services and AI software searches valuable detection points for download, execution, and network telemetry correlation.

Scoring Rationale #

This is a notable AI-themed malware delivery campaign with direct relevance to organizations deploying or evaluating generative AI tools. It does not disclose a new Vidar capability, but it offers actionable detection context around trusted-host abuse, executable downloads, and credential-theft behavior.

Sources #

Primary source and supporting public references used for this report.

Practice with real Ride-Hailing data

90 SQL & Python problems · 15 industry datasets

250 free problems · No credit card

See all Ride-Hailing problems

── more in #ai-tools 4 stories · sorted by recency
── more on @darktrace 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/fake-gemini-installe…] indexed:0 read:3min 2026-08-21 ·