logo

LinkedIn Job Seekers Targeted by Sophisticated “PXA Stealer” Campaign

ID: 42f443bf-fd38-53d1-8634-aafd50a5edce

STIX ID: report--42f443bf-fd38-53d1-8634-aafd50a5edce

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-10

Date Updated: 2026-04-23

Author: Ddos

...
...

A financially motivated campaign attributed to a Vietnam-based cybercriminal group uses compromised LinkedIn accounts and fraudulent recruitment messages to distribute the PXA Stealer. The multi-stage attack funnels victims through Google Forms, shortened URLs, and Dropbox-hosted ZIPs containing a large (~100 MB) DLL that is sideloaded by winword.exe; the payload executes in memory, exfiltrates browser credentials, session cookies (enabling MFA bypass), cryptocurrency wallet data and 2FA artifacts, retrieves C2 from an encrypted Telegram channel, and persists via a scheduled task mimicking a Microsoft Edge update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.