No Manners Here: The Ruthless Rise of The Gentlemen Ransomware

2026-07-11T08:51:41Zfa254e8db0e6e6c0e7f51ea13423b08fbd78a7dcb0e36f99f3472eb4d8e596c7
AI supply chainCVE-2026-0257ClawHubDLL sideloadingGo loaderOpenClawPAN-OSThe GentlemenVertex AIVidarXMRigaffiliatesbucket squattingcloud bucket hijackingcode-signing abusecredential attacksdomain hallucinationsfile inflationglobal namespaceinfostealer','agentic fraudloader-as-a-servicephantom squattingransomwarestealersupply chain

What happened

Unit 42 publishes a broad set of July–June 2026 research and threat briefs covering active exploitation, supply‑chain and cloud risks, and emergent malware trends. Highlights include: the rapid growth of The Gentlemen ransomware via an affiliate model; a Vidar stealer campaign that combines loader‑as‑a‑service, code‑signing abuse, Go‑compiled loaders and DLL sideloading (fake MpClient.dll) often paired with XMRig mining; active exploitation guidance for PAN‑OS (CVE‑2026‑0257); a Vertex AI Python SDK vulnerability enabling RCE via bucket squatting; and research into universal bucket hijacking (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
fa254e8db0e6e6c0e7f51ea13423b08fbd78a7dcb0e36f99f3472eb4d8e596c7
Enrichment time
2026-07-11T08:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · No Manners Here: The Ruthless Rise of The Gentlemen Ransomware · Baitaphish