CRIL researchers detail an active PXA Stealer campaign attributed with high confidence to a Vietnam-based cybercriminal group targeting job seekers across India, Bangladesh, the Netherlands, Sweden, and the US. Threat actors use compromised LinkedIn accounts to distribute fake job offers, funneling victims through Google Forms
Table of contents
Executive SummaryKey TakeawaysOverviewPXA Stealer: History and EvolutionComparative TTP Analysis: PXA Stealer CampaignsWhat Should Businesses Expect When Infected with PXA Stealer?Technical Analysis:ConclusionHow can Cyble help?RecommendationsMITRE ATT&CK MappingSort: