logo

Threat Research: Open-Source Python Script Drives Social Media Phishing Campaign

ID: ecfbbbde-7901-5ce8-aadf-a8609b20ca26

STIX ID: report--ecfbbbde-7901-5ce8-aadf-a8609b20ca26

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-29

...
...

ReliaQuest investigated a LinkedIn-based phishing campaign that used social-media private messages to deliver a WinRAR SFX archive containing a legitimate PDF reader, a malicious DLL for DLL sideloading, and a portable Python interpreter that executed a Base64-encoded open-source pen-testing script in-memory to likely deploy a remote access trojan (RAT). The report details the attack chain (delivery, execution, persistence, and C2), historical examples, detection challenges posed by social platforms and legitimate tooling, and prescribes mitigations including social-media-aware training, application control for Python, and rapid detection/response playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.