← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 7, 2026 · 22:00via Unit 42 (Palo Alto)

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

Brief

A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination.

The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42 .

Read more on Unit 42 (Palo Alto)