Vietnam-Linked PXA Stealer Campaign Exploits LinkedIn to Target Professionals Globally
ID: 8b11e591-3027-5f97-8ba5-9ef3a8e916ee
STIX ID: report--8b11e591-3027-5f97-8ba5-9ef3a8e916ee
Feed Name: The Cyber Express
Threat Score
A global campaign attributed to Vietnam‑linked cybercriminals uses fake recruiter messages on LinkedIn to deliver PXA Stealer — an evolved infostealer employing DLL sideloading, binary padding, memory-only execution and Telegram-based C2 — to harvest credentials, crypto wallets and MFA secrets from professionals across multiple countries, infecting an estimated 94,000 systems and enabling large-scale account takeover, business email compromise, and regulatory exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
