logo

Attackers Leverages LinkedIn to Deliver Remote Access Trojan Targeting Corporate Environments

ID: 96d83432-f510-590b-8be7-3da0dc01b0d5

STIX ID: report--96d83432-f510-590b-8be7-3da0dc01b0d5

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-21

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated LinkedIn phishing campaign delivers weaponized WinRAR self-extracting archives tailored to recipients, which sideload a malicious DLL into a trusted PDF reader process, deploy an in-memory Python payload (via Base64-encoded shellcode runner), and establish persistence with a registry Run key—enabling remote access, lateral movement, and data theft; ReliaQuest investigators reported rapid, multi-stage execution and notable evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.