// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
Breach Record

Baidu

DISCLOSED 2026-01-26 · STOLEN CREDS

The Arsenal-237 malware toolkit uses the legitimately signed but vulnerable Baidu driver BdApiUtil64.sys as a Bring-Your-Own-Vulnerable-Driver (BYOVD) component to gain kernel-level access. This enables attackers to terminate security products, steal credentials, and establish persistence, completely bypassing user-mode defenses. Discovery indicates a critical kernel...

The record

What we know

Disclosed
2026-01-26
Attack vector
Stolen Creds
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the Baidu disclosure. It updates if new public reporting emerges. All tracked breaches →

Baidu just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →