VYPR
researchPublished Jul 21, 2026· 1 source

Vidar Stealer and AsyncRAT Lead Top 10 Malware Families Amid Shifting Threat Actor Tactics

Information stealers and remote access trojans remain dominant, with Vidar and AsyncRAT topping recent malware activity, though overall trends suggest evolving threat actor strategies.

The cyber threat landscape continues to be dominated by a familiar set of malware families, with information stealers and remote access trojans (RATs) serving as the primary tools for initial access, credential theft, and persistent system control. Last week's telemetry highlights Vidar, an information stealer, as the most prevalent family with 282 detections, closely followed by AsyncRAT, a widely abused open-source RAT, which recorded 275 hits. These, along with Remcos and Xworm, which logged 195 and 192 detections respectively, underscore the ongoing reliance of threat actors on modular RATs capable of keylogging, webcam surveillance, and remote desktop control for espionage and financial gain.

While the overall volume of detections for most of the top ten malware families saw a decline week-over-week, the shifts in activity provide crucial insights into evolving threat actor behaviors. AsyncRAT experienced the sharpest drop, with 1,431 fewer detections, a pattern often indicative of infrastructure disruptions, law enforcement actions, or threat actors migrating to successor tools. Conversely, Lumma and Snake Keylogger showed upward trends, with Lumma increasing by 18 detections and Snake by 28, signaling potential reinvestment by Malware-as-a-Service (MaaS) operators and areas where detection coverage may need enhancement.

Vidar, a C++/C-based information stealer active since late 2018, has seen significant development, with its operator releasing Vidar 2.0 in October 2025. This updated version, rewritten in pure C with a multithreaded architecture, coincided with a decline in activity for competing stealers like StealC and Lumma, suggesting a migration of users towards the new Vidar variant. Recent campaigns have leveraged abuse of code-signing certificates, Go-compiled loaders, and DLL sideloading through fake system files to target organizations primarily in the U.S. and EU.

Infection vectors for Vidar are diverse, ranging from malvertising campaigns luring victims to download password-protected archives disguised as pirated software, to multi-stage loaders abusing Windows-native tools. Spam emails with malicious attachments and bundled freeware also serve as common entry points. Vidar's operational model as a MaaS, with a 'PRO' tier priced around $700, makes it accessible to a wide range of cybercriminals. Its broad targeting means it affects various commercial sectors, and it has also been observed as a secondary payload in STOP/DJVU ransomware intrusions.

AsyncRAT, an open-source .NET/C# RAT first released in 2019, remains a potent tool due to its availability and extensive features. Despite its recent decline in detections, it has over 40 active forks and is frequently used for its capabilities in espionage and financial theft. Common infection vectors include phishing emails with malicious attachments like .wsf scripts or OneNote files, malicious Excel spreadsheets, and Dropbox links leading to multi-stage scripts. It has also been observed exploiting vulnerabilities such as CVE-2022-30190 (Follina/MSDT).

The telemetry data indicates a geographical concentration of AsyncRAT activity in Ecuador, Colombia, and Brazil, with significant targeting of the financial services and education sectors. This distribution highlights the global reach of these threats and the need for robust defenses across various industries and regions. The reliance on social engineering, living-off-the-land techniques, and the exploitation of legitimate system tools rather than specific CVEs for Vidar, and the modular nature of AsyncRAT, present ongoing challenges for defenders.

The fluctuating popularity of these malware families underscores the dynamic nature of the cybercrime ecosystem. Defenders must remain vigilant, monitoring not only the emergence of new threats but also the shifts in activity and tooling among established malware families. Understanding these trends, such as the rise of Vidar and the potential migration from AsyncRAT, is critical for prioritizing security efforts and adapting detection and response strategies.

Synthesized by Vypr AI