No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
2026-07-11T08:51:41Z•fa254e8db0e6e6c0e7f51ea13423b08fbd78a7dcb0e36f99f3472eb4d8e596c7
AI supply chainCVE-2026-0257ClawHubDLL sideloadingGo loaderOpenClawPAN-OSThe GentlemenVertex AIVidarXMRigaffiliatesbucket squattingcloud bucket hijackingcode-signing abusecredential attacksdomain hallucinationsfile inflationglobal namespaceinfostealer','agentic fraudloader-as-a-servicephantom squattingransomwarestealersupply chain
What happened
Unit 42 publishes a broad set of July–June 2026 research and threat briefs covering active exploitation, supply‑chain and cloud risks, and emergent malware trends. Highlights include: the rapid growth of The Gentlemen ransomware via an affiliate model; a Vidar stealer campaign that combines loader‑as‑a‑service, code‑signing abuse, Go‑compiled loaders and DLL sideloading (fake MpClient.dll) often paired with XMRig mining; active exploitation guidance for PAN‑OS (CVE‑2026‑0257); a Vertex AI Python SDK vulnerability enabling RCE via bucket squatting; and research into universal bucket hijacking (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- fa254e8db0e6e6c0e7f51ea13423b08fbd78a7dcb0e36f99f3472eb4d8e596c7
- Enrichment time
- 2026-07-11T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.