Cyber criminals have been tricking users searching for the Google Gemini AI tool by offering a counterfeit installer—only to deploy the Vidar information stealer. The malware targets browser-saved credentials, putting email, financial, and business accounts at risk. The campaign was uncovered by Darktrace in July 2026 in the EMEA region when analysts noticed suspicious executables, odd network behaviour, and credential theft tracing back to the fake Gemini installer. ([cybersecuritynews.com](https://cybersecuritynews.com/fake-google-gemini-installer/))
How the Infection Chain Operates
The attack starts with file searches leading to a document named Download_Google_Gemini_For_Windows.exe, which in turn links to a Google Colab page staged as a download source. From there, users are redirected to what appears to be a legitimate site dubbed “Windows Software Hub” to download the fake Gemini installer. ([cybersecuritynews.com](https://cybersecuritynews.com/fake-google-gemini-installer/))
Users are then instructed—via a bundled README—to run the executable with administrator privileges and exclude it from antivirus scans. Once executed, the binary—compiled in Go—connects over port 443 to external infrastructure, including Telegram servers, and starts collecting browser credentials. ([cybersecuritynews.com](https://cybersecuritynews.com/fake-google-gemini-installer/))
Credentials Stolen & Response Measures
Vidar’s core goal is to harvest saved browser passwords, session tokens, and similar sensitive data—allowing attackers access to private accounts and services without needing to break passwords. Endpoint timestamp & SSL certificate analysis during the investigation flagged connections to suspect IPs and C2 domains. ([cybersecuritynews.com](https://cybersecuritynews.com/fake-google-gemini-installer/))
Darktrace’s containment involved blocking communications with malicious infrastructure and isolating the affected endpoint. Crucially, the detection hinged on anomalous behaviour rather than trusting the installer’s presentation or its hosting platforms. ([cybersecuritynews.com](https://cybersecuritynews.com/fake-google-gemini-installer/))
Practical Takeaways for Users and Organizations
Any download that claims to be Google Gemini—or any AI tool—should be treated like any other software: verify the source. Don’t rely on search results that lead through unfamiliar hosts. Avoid disabling antivirus tools or adding exceptions without careful consideration. ([cybersecuritynews.com](https://cybersecuritynews.com/fake-google-gemini-installer/))
Organizations should monitor for unusual access to browser credential stores, new executables launched from Downloads folders, and unfamiliar encrypted outbound connections from freshly installed programs. These signals often precede a breach. ([cybersecuritynews.com](https://cybersecuritynews.com/fake-google-gemini-installer/))
The campaign underlines a growing trend: attackers are turning strong interest in AI tools into fresh opportunities for social engineering and credential theft. Protecting software supply chains—not just known vulnerabilities—has become essential in today’s threat landscape.