CURRENT THEAT INTEL: LinkedIn Spoof Phishing Scam Delivers ConnectWise RAT

CYBERInsights ! Small Business Cybersecurity
Image Credit: Open Grid Scheduler_Flickr

Helping Keep Small Business CYBERSafe!
Gibraltar: Monday 10th March 2025 at 09:04 CET

CURRENT THEAT INTEL: LinkedIn Phishing Scam Delivers ConnectWise RAT using fake LinkedIn InMail notifications
By: Iain FraserCybersecurity Journalist
CYBERInsights – The UK Small Business Cybersecurity Network
#CyberInsights #CyberSecurity #CyberAwareness #CyberSafe #SME #SmallBusiness #LinkedIn #Phishing #RAT

A newly discovered phishing campaign is using fake LinkedIn InMail notifications to distribute the ConnectWise Remote Access Trojan (RAT), according to Cybersecurity intelligence firm Cofense. Unlike traditional LinkedIn phishing scams that aim to steal login credentials, this attack delivers malware directly to the victim’s device.

The fraudulent emails, which claim to be from a sales director requesting a quote, closely mimic LinkedIn’s branding. However, they use an outdated InMail template from before LinkedIn’s 2020 UI refresh—making them particularly convincing for long-time users. Clicking on the embedded “Read More” or “Reply To” buttons triggers the download of the ConnectWise RAT installer.

This attack was identified on a system protected by Microsoft Defender for Endpoint, underscoring the need for businesses to stay vigilant against evolving phishing tactics. Security teams are urged to educate employees on spotting #Phishing attempts and to ensure their endpoint protection solutions are equipped to detect and block such threats.

CYBERInsights | Practical Small Business Cybersecurity
Image Credit: IfOnlyCommunications

UK SME Owner/Adviser? Join SMECyber Free Now! & Access the SME Cyber Forum – Read, Learn, Engage, Share …

The Latest SME Cybersecurity News, Threat Intelligence & Analysis, Timely Scam Alerts, Best-practice Compliance, Mitigation & Resources specifically curated for UK Based SMEs in a Single Weekly Email direct to your Inbox or Smart Device together with Unrestricted Free Access to our entire SME Cyber Knowledge & Tutorial Library.

What is a VPN & Does my SME Need one? A VPN is a Virtual Private Network a method of securing your communications credentials. When it comes to Small and Medium-sized enterprises (SMEs), the choice of VPNs can significantly impact the security and efficiency of their operations.

The NordVPN service allows you to connect to 5600+ servers in 60+ countries. It secures your Internet data with military-grade encryption, ensures your web activity remains private and helps bypass geographic content restrictions online.  Join NordVPN Today and Save up to 73% and Get 3 months Extra Free – Rude Not to …!