The game, called PirateFi, was not just an innocent title that had been compromised—it was built from the ground up as a Trojan horse to distribute the powerful Vidar infostealer malware. The Vidar malware is an advanced infostealer capable of exfiltrating vast amounts of data from infected computers. Vidar has been linked to multiple cybercriminal operations in the past, including campaigns targeting hotel booking credentials, deploying ransomware, and injecting malicious advertisements into Google search results. Health Sector Cybersecurity Coordination Center (HC3) described Vidar as “one of the most successful infostealers,” with its reach growing since its discovery in 2018. What makes Vidar particularly dangerous is its availability through the malware-as-a-service model, meaning it can be purchased and used by even low-skill cybercriminals. Genheimer noted that Vidar is widely used by many different cybercriminals, making it unclear who was responsible for this specific attack. Each sample exhibited identical functionality, confirming that PirateFi was specifically designed to distribute Vidar. Read more in our articles including "Hackers Planted Malware in a Steam Game to Steal Gamers’ Passwords—Here’s What Happened" and "MLBB opens 2026 Global Skin Design Contest with USD 49,000 prize pool".
The game, called PirateFi, was not just an innocent title that had been compromised—it was built from the ground up as a Trojan horse to distribute the powerful Vidar infostealer malware. The Vidar malware is an advanced infostealer capable of exfiltrating vast amounts of data from infected computers.
Vidar has been linked to multiple cybercriminal operations in the past, including campaigns targeting hotel booking credentials, deploying ransomware, and injecting malicious advertisements into Google search results. Health Sector Cybersecurity Coordination Center (HC3) described Vidar as “one of the most successful infostealers,” with its reach growing since its discovery in 2018. What makes Vidar particularly dangerous is its availability through the malware-as-a-service model, meaning it can be purchased and used by even low-skill cybercriminals.
Our coverage of Vidar infostealer includes: "Hackers Planted Malware in a Steam Game to Steal Gamers’ Passwords—Here’s What Happened"; "MLBB opens 2026 Global Skin Design Contest with USD 49,000 prize pool"; "Europe enters the MLBB esports scene with first PGL Mobile Legends Challengers tournament". Each article provides unique insights and information.