Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

2026-07-08T08:51:38Z0ad361e41b9c08423c89a3999149f386f1088cfa841b8b3403c5cabb31c7b26f
AI supply chainDLL sideloadingGo loaderMicrosoft Teams phishingMpClient.dllOpenClawPAN-OS CVE-2026-0257TinyRCTVertex AIVidarXMRigbucket hijackingcloud logging abusecode signing abusecredential stuffingcross-tenant RCEdomain hijackingespionageglobal namespaceloader-as-a-servicemacOS Tahoe 26 artifactnpm supply chainphantom squattingpickle/deserialization RCEsupply chain

What happened

A collection of Unit42 research and threat briefs covering active malware campaigns, supply‑chain and cloud risks, and multiple discovery of exploitable flaws. Highlights include a Vidar stealer campaign using loader‑as‑a‑service, code‑signing abuse, Go‑compiled loaders and DLL sideloading (fake MpClient.dll) alongside XMRig miner activity; AI supply‑chain threats (OpenClaw/ClawHub skills, phantom squatting of hallucinated domains); cloud bucket/global namespace hijacking and a Vertex AI Python SDK vulnerability enabling cross‑tenant RCE via bucket squatting; credential stuffing/large‑scale CR

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
0ad361e41b9c08423c89a3999149f386f1088cfa841b8b3403c5cabb31c7b26f
Enrichment time
2026-07-08T08:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation · Baitaphish