Cybersecurity researchers have uncovered a new phishing that exploits private messages on social to spread malicious payloads, possibly with the aim of deploying a remote access trojan (RAT).

The attackers are delivering “weaponized files via Dynamic Link Library (DLL) sideloading, combined with a legitimate, open-source Python pen-testing script,” ReliaQuest.
See also: Evelyn stealer exploits VS Code extensions
Malware distribution via LinkedIn messages
The attack targets “high-value” individuals via messages sent on LinkedIn. The attackers’ goal is to trick victims into downloading a malicious WinRAR self-extracting archive (SFX). Once executed, the archive extracts four different items:
– A legitimate open source PDF reader app
– A malicious DLL loaded by the PDF reader application
– A portable executable (PE) of the Python interpreter
– A RAR file that is likely used as bait
DLL sideloading
The infection chain is triggered when the PDF reader application is executed, causing the malicious DLL. The use of DLL sideloading has become an increasingly common technique adopted by malicious actors to evade detection and hide signs of malicious activity by exploiting legitimate processes.
Last week, at least three campaigns leveraged DLL sideloading to deliver malware, tracked as LOTUSLITE and PDFSIDER, along with other common trojans and infostealers.
See also: Discord becomes an attack tool for distributing malware

In the campaign observed by ReliaQuest, the sideloaded DLL is used to install the Python interpreter on the system and create a Windows Registry Run key that ensures that the Python interpreter is automatically executed on every login. The interpreter's primary responsibility is to execute a Base64-encoded open-source shellcode that is executed directly in memory to avoid creating forensic artifacts on disk.
The final payload attempts to communicate with an external server, providing attackers with persistent remote access to the compromised computer and extracting data.
The misuse of legitimate open source tools, combined with the use of phishing messages sent on social media platforms (e.g. LinkedIn), shows that phishing attacks are not limited to emails and that alternative delivery methods can exploit security gaps to increase the chances of success and penetrate corporate environments.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
ReliaQuest told The Hacker News that the campaign appears to be broad and opportunistic, with activity spanning multiple sectors and regions.
“This approach allows attackers to bypass detection and scale their operations with minimal effort, while maintaining persistent control over compromised systems,” the cybersecurity firm said. “Once inside, they can escalate their privileges, move laterally across networks, and extract data.”
See also: SolyxImmortal abuses Discord for data theft

LinkedIn misuse for hacking attacks
This is not the first time that LinkedIn has been abused for targeted attacks. In recent years, several North Korean malicious actors, including those associated with the CryptoCore and Contagious Interview, have targeted victims by contacting them on LinkedIn (under the guise of a job opportunity). The hackers convince the victims to perform a malicious task as part of a supposed evaluation or code review.
In March 2025, Cofense also described a LinkedIn-themed phishing campaign that used baited LinkedIn InMail notifications to trick recipients into clicking a “Read More” or “Reply” button. The goal was to get them to download remote desktop software to take full control of the victims’ computers.
“Social media platforms commonly used by businesses represent a security gap for most organizations,” ReliaQuest said. “Unlike email, where organizations tend to have security monitoring tools, private messages on social media lack visibility and security controls, making them an attractive delivery channel.”
