{"slug": "fake-gemini-installer-delivers-vidar-credential-stealer", "title": "Fake Gemini Installer Delivers Vidar Credential Stealer", "summary": "Darktrace investigated a July 2026 intrusion in which a user at an EMEA customer downloaded a fake Google Gemini installer that delivered the Vidar information stealer. The lure used a Google Colab page that redirected users to a fraudulent download site, and the payload targeted browser credentials. Darktrace's Autonomous Response system quarantined the infected device.", "body_md": "# Fake Gemini Installer Delivers Vidar Credential Stealer\n\nDarktrace investigated a July 2026 intrusion in which a user at an EMEA customer downloaded a fake Google Gemini installer that delivered the Vidar information stealer. According to Darktrace, the lure used a Google Colab page that redirected users to a fraudulent download site, while the payload targeted browser credentials. Darktrace reported that its response system quarantined the infected device.\n\nDarktrace investigated a July 2026 intrusion in which a malicious executable impersonating a Google Gemini installer delivered the Vidar information stealer to a customer environment in the Europe, Middle East and Africa region. The incident used Google Colab as part of a deceptive software-download path, according to Darktrace's incident report.\n\nThe file was named Download_Google_Gemini_For_Windows.exe. Help Net Security, citing Darktrace's analysis, reports that a search result associated with the suspicious filename led to a Google Colab page, which then redirected users to micronsoftwares[.]com, a site presented as a \"Windows Software Hub.\"\n\n### Trusted services in the delivery chain\n\nGoogle Colab is a legitimate browser-based Jupyter notebook platform used for code execution and machine learning workloads. Darktrace reported that SSL connections to Google Colab immediately preceded execution of the suspicious binary in the affected environment. The researchers described that timing as evidence consistent with a user interacting with the Colab-hosted lure before reaching the download site.\n\nDarktrace could not conclusively reconstruct the full download chain from HTTP or file-download telemetry, according to reporting by GBHackers. At the time of Darktrace's July 15 review, the Colab page remained active and contained the executable, GBHackers reported.\n\nThe downloaded ZIP archive included a README file instructing users to run the executable with administrator privileges and add it to antivirus exclusions, according to Help Net Security. Those instructions are established social-engineering techniques that can reduce endpoint defenses before malware execution.\n\n### Vidar behavior and containment\n\nDarktrace identified the payload as a newer Go-compiled variant of **Vidar**, an information stealer. According to Help Net Security, the malware communicated with Telegram-based infrastructure and used dtm[.]kijangturbo88[.]top as a command-and-control endpoint.\n\nDarktrace identified suspicious process activity, anomalous network communications, and indicators of credential theft during the incident. Help Net Security reports that a separate endpoint-protection detection later supported the assessment that the activity targeted browser credentials. Darktrace's Autonomous Response system blocked communications with malicious infrastructure and quarantined the infected device, the firm reported.\n\nThe malware itself was not novel, but researchers characterized the AI-themed lure and delivery mechanism as notable. For security teams, the incident illustrates a broader pattern: software acquisition workflows, especially searches for popular AI tools, can become an initial-access path when users encounter convincing branding and legitimate cloud services. Controls that inspect newly downloaded executables, correlate browser or cloud-service activity with process execution, and flag requests to disable endpoint protections can help surface this type of campaign even when the initial hosting service is trusted.\n\n## Key Points\n\n- 1Darktrace traced a Vidar infection to a fake Gemini installer, with Google Colab used in the deceptive download workflow.\n- 2The Go-compiled Vidar variant targeted browser credentials and communicated with Telegram-based command-and-control infrastructure, according to Darktrace.\n- 3Comparable campaigns make trusted cloud services and AI software searches valuable detection points for download, execution, and network telemetry correlation.\n\n## Scoring Rationale\n\nThis is a notable AI-themed malware delivery campaign with direct relevance to organizations deploying or evaluating generative AI tools. It does not disclose a new Vidar capability, but it offers actionable detection context around trusted-host abuse, executable downloads, and credential-theft behavior.\n\n## Sources\n\nPrimary source and supporting public references used for this report.\n\nPractice with real Ride-Hailing data\n\n90 SQL & Python problems · 15 industry datasets\n\n250 free problems · No credit card\n\n[See all Ride-Hailing problems](/problems/datasets/mobility)", "url": "https://wpnews.pro/news/fake-gemini-installer-delivers-vidar-credential-stealer", "canonical_source": "https://letsdatascience.com/news/fake-gemini-installer-delivers-vidar-credential-stealer-6a36b7ec", "published_at": "2026-08-21 06:22:04+00:00", "updated_at": "2026-08-21 08:12:33.144625+00:00", "lang": "en", "topics": ["ai-tools"], "entities": ["Darktrace", "Google Gemini", "Vidar", "Google Colab", "Help Net Security", "GBHackers"], "alternates": {"html": "https://wpnews.pro/news/fake-gemini-installer-delivers-vidar-credential-stealer", "markdown": "https://wpnews.pro/news/fake-gemini-installer-delivers-vidar-credential-stealer.md", "text": "https://wpnews.pro/news/fake-gemini-installer-delivers-vidar-credential-stealer.txt", "jsonld": "https://wpnews.pro/news/fake-gemini-installer-delivers-vidar-credential-stealer.jsonld"}}