// GeminiHIGH
Attackers deployed a fake Google Gemini installer masquerading as legitimate Windows software, hosted on Google Colab, to deliver the Vidar infostealer malware. The Go-compiled malware communicates via Telegram-based command-and-control infrastructure and targets browser credentials and sensitive data. Researchers observed at least one confirmed infection in a company network in the EMEA region.
- Fake Gemini installer delivers Vidar infostealer via Google Cola(opens in a new tab)
- Fake Gemini installer delivers Vidar infostealer via Google Cola(opens in a new tab)
- Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer(opens in a new tab)
- Week in review: Records allegedly stolen from Azure tenants, Med(opens in a new tab)
// Get alerts for Gemini