// Alert

Gmail threat report

Threat actors distributed a fake Google Gemini installer via Google Colab in July 2026 to deliver the Vidar information stealer. The campaign targeted users seeking AI tools, redirecting them through a spoofed Windows Software Hub to download malware that harvested browser credentials, including saved Gmail passwords and session data. Darktrace detected the compromise through behavioral analysis and blocked C2 communications.

// Get alerts for Gmail