
A new attack campaign, uncovered by Palo Alto Networks Unit 42 researchers, is using fake Google advertisements to push malicious software onto people’s computers. The ads appear in search results when you look for popular paid programs, and they promise a free download. Once you install the software, two hidden programs run quietly in the background: Vidar, which copies your saved passwords, cookies, and payment details from your browser; and XMRig, which secretly uses your computer’s processing power to mine cryptocurrency — slowing your device down and driving up your electricity bill.
Unit 42 found 99 samples of the malicious installer, all using a tool called Factory-v3 to bundle the two programs together. The campaign targets both everyday users and small businesses worldwide, with stolen credentials being sold on criminal marketplaces. The fake download pages use the branding of JustWatch, a legitimate streaming guide service — JustWatch itself was not compromised. Attackers communicate with infected machines through Telegram, collecting new victim data in real time.
How to check if you’re affected
Affected devices are Windows computers where you recently downloaded software from a search result advertisement rather than the software’s official website.
- If you downloaded any program from a search ad that claimed to offer a free or cracked version of paid software, treat it as suspicious and delete it immediately.
- Run a full scan with your antivirus program. This malware is commonly detected as Vidar Stealer or XMRig Miner.
- Check your browser’s saved passwords and change passwords for important accounts — especially email, banking, and shopping sites — in case your credentials were copied.
