logo

Threat Actors Exploit LinkedIn for RAT Delivery in Enterprise Networks

ID: 0fc8d321-2355-5777-ab39-411915d7dd5f

STIX ID: report--0fc8d321-2355-5777-ab39-411915d7dd5f

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-21

Date Updated: 2026-05-08

Author: Mayura Kathir

...
...

**Executive Summary:** A sophisticated LinkedIn-based phishing campaign distributes WinRAR SFX archives that sideload a malicious DLL and deploy a portable Python interpreter to execute Base64-encoded open-source shellcode runners in memory, resulting in RAT deployment with persistent registry autorun and observed C2 activity; the report outlines social engineering tactics, DLL sideloading and in-memory execution techniques, and recommends social-media-specific user training, application control, and endpoint monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.