Fake Google Gemini Installer Delivers Vidar Infostealer, Stealing Browser Credentials in EMEA Enterprise
What Happened — A malicious executable named Download_Google_Gemini_For_Windows.exe was advertised on a Google Colab notebook and redirected users to a fake “Windows Software Hub.” When run with administrator privileges, the file installed a Go‑compiled Vidar infostealer that harvested browser passwords and sent them to a Telegram‑based command‑and‑control server. Darktrace’s autonomous response blocked the C2 traffic and quarantined the endpoint.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a credential‑compromise scenario that SOC 2 Access Control (CC6.1) and Security Awareness (CC6.2) criteria are designed to prevent and document.
- Continuous monitoring of privileged‑execution events and retaining a defensible audit trail of endpoint detections provide the evidence auditors expect.
- Verisq’s SOC2 Access Controls capability automates collection of admin‑run alerts and policy‑violation logs, simplifying SOC 2 evidence gathering.
Who Is Affected — Enterprises across technology, professional services, and any organization where employees download software from the web; the case was observed in an EMEA‑based corporate network.
Recommended Actions
- Map the incident to SOC 2 CC6.1 (access control) and CC6.2 (security awareness) controls; ensure evidence of admin‑privilege usage is collected.
- Enforce least‑privilege policies and require multi‑factor authentication for any elevation of privilege.
- Deploy security‑awareness training that includes AI‑themed social‑engineering examples and verify that users validate download sources.
- Integrate endpoint detection data into a continuous‑compliance dashboard for real‑time audit evidence. Source: https://www.helpnetsecurity.com/2026/08/20/fake-google-gemini-installer-vidar-infostealer/
Technical Notes — The lure leveraged a trusted Google Colab URL, then redirected to a malicious site hosting a Go‑compiled Vidar variant. The malware communicated with dtm.kijangturbo88.top over Telegram. The installer instructed victims to add it to AV exceptions and run as admin. Source: https://www.helpnetsecurity.com/2026/08/20/fake-google-gemini-installer-vidar-infostealer/