Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
2026-07-08T08:51:38Z•0ad361e41b9c08423c89a3999149f386f1088cfa841b8b3403c5cabb31c7b26f
AI supply chainDLL sideloadingGo loaderMicrosoft Teams phishingMpClient.dllOpenClawPAN-OS CVE-2026-0257TinyRCTVertex AIVidarXMRigbucket hijackingcloud logging abusecode signing abusecredential stuffingcross-tenant RCEdomain hijackingespionageglobal namespaceloader-as-a-servicemacOS Tahoe 26 artifactnpm supply chainphantom squattingpickle/deserialization RCEsupply chain
What happened
A collection of Unit42 research and threat briefs covering active malware campaigns, supply‑chain and cloud risks, and multiple discovery of exploitable flaws. Highlights include a Vidar stealer campaign using loader‑as‑a‑service, code‑signing abuse, Go‑compiled loaders and DLL sideloading (fake MpClient.dll) alongside XMRig miner activity; AI supply‑chain threats (OpenClaw/ClawHub skills, phantom squatting of hallucinated domains); cloud bucket/global namespace hijacking and a Vertex AI Python SDK vulnerability enabling cross‑tenant RCE via bucket squatting; credential stuffing/large‑scale CR
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 0ad361e41b9c08423c89a3999149f386f1088cfa841b8b3403c5cabb31c7b26f
- Enrichment time
- 2026-07-08T08:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.