logo

Linkedin Phishing Campaign Exploits Open-Source Pen Testing Tool to Compromise Business Execs

ID: 93118834-49bd-5d9c-a6e4-a11eafe07e36

STIX ID: report--93118834-49bd-5d9c-a6e4-a11eafe07e36

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

...
...

ReliaQuest details a LinkedIn-based phishing campaign aimed at high-value individuals in which attackers send industry-tailored messages containing a malicious WinRAR SFX that extracts a legitimate PDF reader alongside a malicious DLL. The DLL uses DLL sideloading to evade detection and a legitimate open-source penetration-testing tool is abused to achieve persistence, data exfiltration, privilege escalation, and lateral movement; researchers recommend treating social-media links like email phishing, implementing social-media security training, and auditing personal account use on corporate devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.