Published on August 20, 2026

Fake Gemini installer delivers Vidar infostealer via Google Colab lure


Severity
High

Detail

Security researchers have identified a campaign using a fake Google Gemini installer to deliver the Vidar information-stealing malware to Windows users. The campaign abuses trusted Google services and AI-related search interest to make the malicious software appear legitimate. The activity was observed on a company network in the EMEA region. The attackers used Google Colab, a legitimate cloud-based platform commonly used for development and machine learning, to host or promote the fake installer. By using a trusted Google platform, the attackers increased the likelihood that victims would consider the download legitimate.

How?

The attack begins when users search for a Google Gemini application for Windows. A malicious Google Colab page appears in search results and presents a download prompt for a fake Gemini installer.

The victim is then redirected to a fraudulent website posing as a Windows Software Hub, where an executable named Download_Google_Gemini_For_Windows.exe is provided. The use of legitimate Google infrastructure and AI-themed content helps the malicious download appear trustworthy.

The downloaded ZIP archive contains a README instructing victims to execute the installer with administrator privileges and add it to their antivirus exclusion list. Once executed, the file delivers a newer Go-compiled Vidar infostealer.

Vidar communicates with attacker-controlled infrastructure, including a Telegram-based command-and-control channel, and is capable of stealing browser credentials and other sensitive information from the compromised system. Endpoint telemetry subsequently confirmed activity consistent with browser credential theft and data collection.

The campaign demonstrates how threat actors are increasingly abusing AI-themed lures, search engine results, and trusted cloud platforms to distribute malware. Blocking only known malicious domains may be insufficient because legitimate services such as Google Colab can be used during the delivery process.

Recommendation

Organizations should implement a layered security approach to reduce the risk of Vidar and similar infostealer infections:

  • Download AI applications only from official vendor websites and trusted application stores.
  • Educate users to avoid software downloads promoted through suspicious search results or unofficial websites.
  • Monitor for suspicious executables downloaded from cloud platforms such as Google Colab.
  • Prevent users from unnecessarily adding downloaded applications or files to antivirus exclusions.
  • Monitor endpoints for suspicious browser credential access and unusual outbound connections.
  • Use EDR solutions to detect suspicious installer execution, credential theft, and abnormal process activity.

Source

https://www.helpnetsecurity.com/2026/08/20/fake-google-gemini-installer-vidar-infostealer