Attackers Leverages LinkedIn to Deliver Remote Access Trojan Targeting Corporate Environments
ID: 96d83432-f510-590b-8be7-3da0dc01b0d5
STIX ID: report--96d83432-f510-590b-8be7-3da0dc01b0d5
Feed Name: cybersecurityNews.com
Threat Score
A sophisticated LinkedIn phishing campaign delivers weaponized WinRAR self-extracting archives tailored to recipients, which sideload a malicious DLL into a trusted PDF reader process, deploy an in-memory Python payload (via Base64-encoded shellcode runner), and establish persistence with a registry Run key—enabling remote access, lateral movement, and data theft; ReliaQuest investigators reported rapid, multi-stage execution and notable evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
