A new LinkedIn phishing scam is targeting executives online – make sure you don’t fall for this

  • Sophisticated LinkedIn phishing uses fake job ads to target executives
  • Attacks employ DLL sideloading and Python tools to install remote access trojans
  • ReliaQuest warns phishing extends beyond email, exploiting overlooked social media platforms

Business executives and IT admins are being targeted by a highly sophisticated phishing attack which doesn’t happen in the email inbox but rather – on LinkedIn.

Security researchers ReliaQuest said they saw a new attack that combines legitimate Python pentesting projects, DLL sideloading, and fake job ads, to infect “high-value targets” with remote access trojans (RAT).

As per ReliaQuest’s report, the victims are carefully chosen and reached out with an invitation to a business project or a job. The LinkedIn message comes with a download link which, if clicked, downloads a WinRAR self-extracting archive (SFX). The filename is usually tailored to the victim’s role, such as a product roadmap or project plan.

Deploying the RAT

When the victim opens the archive, it automatically extracts several files to the same folder, making the package look legitimate. The victim then launches the PDF reader that’s included in the archive, believing they are opening a normal document.

This reader then loads a malicious DLL that was also included in the archive. This method, known as DLL sideloading, executes the attacker’s code without raising immediate security alerts, it was explained.

The malicious DLL adds a Windows registry “Run” key to establish persistence and then runs a portable Python interpreter that was also included in the archive. This tool runs a Base64-encoded, open-source hacking tool directly in memory.

In turn, the malware begins communicating with a command-and-control server, which is standard behavior for remote access trojans.

“This campaign serves as a reminder that phishing isn’t confined to email inboxes. Phishing attacks take place over alternative channels like social media, search engines, and messaging apps – platforms that many organizations still overlook in their security strategies,” ReliaQuest said.

“Social media platforms, especially those frequently accessed on corporate devices, provide attackers with direct access to high-value targets like executives and IT administrators, making them invaluable to cybercriminals.”

Via Cybernews

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

T-Mobile will live translate regular phone calls without an app

Even an old flip phone should be able to use T-Mobile’s Live Translation. | Illustration: Alex Castro / The Verge T-Mobile is preparing to test...

El Paso flights resume after Mexican cartel drones reportedly trigger airspace closure

The Federal Aviation Administration has lifted its temporary closure to the airspace around El Paso International Airport in Texas, after originally saying that all...

Pokopia turns the Pokémon world into a relaxing, human-free paradise

Though catching monsters and making them fight have always been core elements of the Pokémon brand, spinoffs like the Pokémon Snap and Detective Pikachu...

The Halide app’s anti-algorithm camera mode looks better with a little processing

Backlit is back. | Photo: Allison Johnson / The Verge Something happens every time I try to use an iPhone camera like a real camera. Here's...

How an ‘icepocalypse’ raises more questions about Meta’s biggest data center project

Donna Collins lives about 20 miles from where Meta's biggest data center is being built, in a house her family has lived in for...

The Switch 2’s GameShare multiplayer turns this horror game into an unexpected comedy

GameShare, a multiplayer feature that's exclusive to the Switch 2, is a neat concept that so far has mostly been used in pretty standard...

Diesel’s wired earbuds look exactly like wired earbuds from Diesel

Despite evidence to the contrary, not only are wired earbuds alive and well, they're enjoying a resurgence. Brands like Belkin and even respected headphone...

Reanimal wants to devour you

The woods in Reanimal are full of surprises. You will encounter human cadavers that slither like snakes, gigantic talking pigs, and, at one point,...

Here are the brands bringing ads to ChatGPT

OpenAI officially launched its advertising pilot in ChatGPT, leaving us with a better idea of the kinds of products we might see stuffed beneath...

Mullvad VPN review: Near-total privacy with a few sacrifices

Mullvad, a virtual private network (VPN) named after the Swedish word for "mole," is often recognized as one of the best VPNs for privacy....