LinkedIn Job Seekers Targeted by Sophisticated “PXA Stealer” Campaign
ID: 42f443bf-fd38-53d1-8634-aafd50a5edce
STIX ID: report--42f443bf-fd38-53d1-8634-aafd50a5edce
Feed Name: securityonline.info
A financially motivated campaign attributed to a Vietnam-based cybercriminal group uses compromised LinkedIn accounts and fraudulent recruitment messages to distribute the PXA Stealer. The multi-stage attack funnels victims through Google Forms, shortened URLs, and Dropbox-hosted ZIPs containing a large (~100 MB) DLL that is sideloaded by winword.exe; the payload executes in memory, exfiltrates browser credentials, session cookies (enabling MFA bypass), cryptocurrency wallet data and 2FA artifacts, retrieves C2 from an encrypted Telegram channel, and persists via a scheduled task mimicking a Microsoft Edge update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
