Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
2026-07-08T20:51:39Z•3799550d38b47419a84e150ad214d41fdb0fab6745e4faedb22d5d6da8515e82
AI supply chainDLL sideloadingGo loaderMicrosoft Teams phishingPAN-OSTinyRCTVertex AIVidarbucket hijackingcloud logging manipulationcode signing abusecredential attacksespionageloader-as-a-servicemacOS forensic artifactnpm supply chainphantom squattingremote code executionstealersupply chainxmrig
What happened
Unit 42 roundup covering multiple active and emerging threats: a Vidar stealer campaign that combines code-signing abuse, Go-compiled loaders and DLL sideloading (fake MpClient.dll) with Xmrig miner activity; AI-related supply-chain risks including phantom-squatting domains, malicious skills in agent marketplaces (OpenClaw) and integrity issues for AI agents; cloud-focused attacks such as universal bucket hijacking and a Vertex AI Python SDK bucket-squatting RCE; active exploitation of PAN-OS (CVE-2026-0257); large-scale credential attacks and Microsoft Teams phishing campaigns; targeted SE-亞洲
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 3799550d38b47419a84e150ad214d41fdb0fab6745e4faedb22d5d6da8515e82
- Enrichment time
- 2026-07-08T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.