Darktrace and Google: Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

Darktrace and Google: Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

Cybercriminals Exploit AI Hype to Distribute Vidar Stealer via Fake Google Gemini Installer

In July 2026, threat actors leveraged the growing interest in generative AI to distribute the Vidar information stealer through a fake Google Gemini installer hosted on Google Colab. Darktrace uncovered the campaign after investigating a compromise in an EMEA-based customer environment, where a user downloaded and executed a malicious file named Download_Google_Gemini_For_Windows.exe.

Unlike traditional phishing attacks, this campaign exploited trust in Google’s branding and cloud services. Victims searching for AI tools were directed to a Google Colab page a legitimate Jupyter notebook service displaying a download prompt. The page redirected users to micronsoftwares[.]com, a spoofed "Windows Software Hub" offering the fake installer. While the full download chain couldn’t be reconstructed, SSL sessions to Google Colab preceded the execution of the malicious binary, strongly suggesting the Colab page as the initial infection vector.

The downloaded ZIP archive contained the executable and a README file instructing users to run the binary with administrator privileges and disable antivirus exclusions classic social engineering tactics to bypass security controls. Darktrace identified the payload as a Go-compiled Vidar variant, communicating with Telegram-based command-and-control (C2) infrastructure via dtm[.]kijangturbo88[.]top. Post-execution, the malware connected to 91.98.98[.]86 and 91.98.111[.]49 over TCP/443, exfiltrating browser credentials, session cookies, autofill data, and cryptocurrency wallet artifacts.

Darktrace detected the compromise through behavioral analytics, identifying suspicious process execution from the Downloads folder, anomalous encrypted outbound traffic, and credential-harvesting indicators. Its Autonomous Response capability blocked C2 communications and quarantined the infected endpoint.

The incident highlights a shift in malware distribution tactics, where attackers abuse trusted cloud platforms and AI branding to reduce victim suspicion. By repackaging commodity malware as a legitimate AI tool, threat actors exploit enterprise adoption trends, making detection harder. Organizations are advised to restrict software installations to approved sources, monitor execution from Downloads/temporary directories, and hunt for Gemini-themed installers from unofficial channels.

Indicators of Compromise (IoCs):

"id": "GOODAR1787295076",
"linkid": "google-colab, darktrace",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'location': 'EMEA', 'type': 'Enterprise'}],
 'attack_vector': 'Fake Software Installer (Google Gemini Impersonation)',
 'data_breach': {'data_exfiltration': 'Yes (via C2 communications)',
                 'personally_identifiable_information': 'Yes (browser '
                                                        'credentials, autofill '
                                                        'data)',
                 'sensitivity_of_data': 'High (PII, financial data)',
                 'type_of_data_compromised': ['Browser credentials',
                                              'Session cookies',
                                              'Autofill data',
                                              'Cryptocurrency wallet '
                                              'artifacts']},
 'date_detected': '2026-07',
 'description': 'In July 2026, threat actors leveraged the growing interest in '
                'generative AI to distribute the Vidar information stealer '
                'through a fake Google Gemini installer hosted on Google '
                'Colab. Victims searching for AI tools were directed to a '
                'Google Colab page displaying a download prompt, which '
                'redirected to a spoofed website offering the malicious '
                'installer. The payload was a Go-compiled Vidar variant that '
                'exfiltrated browser credentials, session cookies, autofill '
                'data, and cryptocurrency wallet artifacts.',
 'impact': {'data_compromised': 'Browser credentials, session cookies, '
                                'autofill data, cryptocurrency wallet '
                                'artifacts',
            'identity_theft_risk': 'High (PII and financial data exfiltrated)',
            'operational_impact': 'Potential unauthorized access to user '
                                  'accounts and financial assets',
            'payment_information_risk': 'High (Cryptocurrency wallet artifacts '
                                        'stolen)',
            'systems_affected': 'Endpoint devices of affected users'},
 'initial_access_broker': {'entry_point': 'Fake Google Gemini installer hosted '
                                          'on Google Colab'},
 'investigation_status': 'Investigation Complete (Darktrace)',
 'lessons_learned': 'Attackers abuse trusted cloud platforms and AI branding '
                    'to distribute malware. Organizations should restrict '
                    'software installations to approved sources and monitor '
                    'execution from temporary directories.',
 'motivation': 'Financial Gain (Credential Theft, Cryptocurrency Wallet Theft)',
 'post_incident_analysis': {'root_causes': 'Exploitation of trust in Google '
                                           'branding and cloud services, '
                                           'social engineering tactics (admin '
                                           'privileges and antivirus '
                                           'disablement instructions)'},
 'recommendations': ['Restrict software installations to approved sources',
                     'Monitor execution from Downloads/temporary directories',
                     'Hunt for Gemini-themed installers from unofficial '
                     'channels',
                     'Implement behavioral analytics to detect anomalous '
                     'activity'],
 'references': [{'source': 'Darktrace Investigation'}],
 'response': {'containment_measures': 'Blocked C2 communications, quarantined '
                                      'infected endpoint',
              'enhanced_monitoring': 'Behavioral analytics, detection of '
                                     'suspicious process execution and '
                                     'encrypted outbound traffic',
              'third_party_assistance': 'Darktrace'},
 'title': 'Cybercriminals Exploit AI Hype to Distribute Vidar Stealer via Fake '
          'Google Gemini Installer',
 'type': 'Malware Distribution'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.