Threat Actors Exploit LinkedIn for RAT Delivery in Enterprise Networks
ID: 0fc8d321-2355-5777-ab39-411915d7dd5f
STIX ID: report--0fc8d321-2355-5777-ab39-411915d7dd5f
Feed Name: GBHackers
**Executive Summary:** A sophisticated LinkedIn-based phishing campaign distributes WinRAR SFX archives that sideload a malicious DLL and deploy a portable Python interpreter to execute Base64-encoded open-source shellcode runners in memory, resulting in RAT deployment with persistent registry autorun and observed C2 activity; the report outlines social engineering tactics, DLL sideloading and in-memory execution techniques, and recommends social-media-specific user training, application control, and endpoint monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
