logo

Vietnam-Linked PXA Stealer Campaign Exploits LinkedIn to Target Professionals Globally

ID: 8b11e591-3027-5f97-8ba5-9ef3a8e916ee

STIX ID: report--8b11e591-3027-5f97-8ba5-9ef3a8e916ee

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-04-02

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A global campaign attributed to Vietnam‑linked cybercriminals uses fake recruiter messages on LinkedIn to deliver PXA Stealer — an evolved infostealer employing DLL sideloading, binary padding, memory-only execution and Telegram-based C2 — to harvest credentials, crypto wallets and MFA secrets from professionals across multiple countries, infecting an estimated 94,000 systems and enabling large-scale account takeover, business email compromise, and regulatory exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.