LinkedIn InMailのなりすましマルウェアキャンペーンがConnectWise RATを拡散

LinkedIn InMailのなりすましにより、古いブランド表示と脆弱なメールセキュリティを悪用してConnectWise RATが配布され、組織に重大なリスクをもたらしている。

Written By
Sunny Yadav
Sunny Yadav
Mar 6, 2025
1 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

サイバーセキュリティの防御担当者は、信頼されているLinkedInブランドを悪用した、またも巧妙なフィッシング手口に直面している。

Cofenseが最近詳しく報告したこのキャンペーンでは、LinkedIn InMailの通知を偽装してConnectWise Remote Access Trojan(RAT)を配布する。攻撃者は、正規のビジネスに関する問い合わせを装ったメールで受信者をだまし、気付かないまま悪意あるソフトウェアをダウンロードさせようとしている。

巧妙な偽装を仕掛ける

このキャンペーンのメールは、ネットワーク外の専門家ともやり取りできる機能であるLinkedIn InMailの通知を装い、あたかもLinkedInから送られたかのように綿密に設計されている。しかし、巧妙に隠された手掛かりが偽装を明らかにしている。

  • メールには、LinkedInの2020年以前のインターフェースを思わせる古いテンプレートが使われ、旧デザインに慣れたユーザーの親近感を誘うよう仕組まれている。
  • 見積もりを求める営業部長からのメールを装い、信ぴょう性を高めるため、実在する人物であるCho So-youngのプロフィール画像を流用している。
  • 「DONGJIN Weidmüller Korea Ind.」とされる企業名は、実在する複数の組織名を巧みに組み合わせたものだが、そのような企業は存在しない。

セキュリティプロトコルをすり抜ける

こうした危険信号があったにもかかわらず、メールは最新のセキュリティ防御をすり抜けた。セキュリティヘッダーを分析すると、Sender Policy Framework(SPF)のチェックは、承認されていないIPアドレスが原因でsoftfailとなっていた。

さらに、適切なDomainKeys Identified Mail(DKIM)の署名がないことも、通常は正規のLinkedIn通信に付いているこの署名が欠落していることから、詐欺メールであることをさらに裏付けている。興味深いことに、設定されたDomain-Based Message Authentication, Reporting and Conformance(DMARC)ポリシーは、疑わしいメールを即時に拒否せずスパムとして扱ったため、Microsoft Defender for Endpointのような堅牢なシステムさえも、メールをすり抜けさせる結果となった。

攻撃の仕組み

ユーザーがメール内の「続きを読む」または「返信」ボタンをクリックして操作すると、埋め込まれたリンクがひそかに作動し、ConnectWise RATのインストーラーをダウンロードさせる。

このキャンペーンは、直接的な「ダウンロード」指示を出さない。これはしばしばマルウェアの配布に伴う手口だが、代わりに正規のビジネス問い合わせを装う。この巧妙な手法は、特にLinkedInのメッセージングインターフェースに慣れたユーザーを中心に、慎重なユーザーでさえ警戒を緩めるよう仕向けられている。

Advertisement

組織にとって重要な理由

組織にとって、このように巧妙なフィッシングキャンペーンがもたらす影響は重大だ。この攻撃は、脅威アクターが信頼されているブランドを悪用して人間の心理につけ込み、技術的な防御をすり抜ける手口の典型例である。

攻撃が成功すれば、攻撃者に重要システムへのリモートアクセスを許し、データ侵害や業務の中断、多額の金銭的損失につながる可能性がある。相互接続が進んだ今日のビジネス環境では、堅牢なメール認証対策と継続的な従業員教育を実施することは、単に望ましいだけでなく不可欠だ。一見すると日常的な連絡に思えるものも精査し、高度なセキュリティプロトコルを導入してデジタル資産を保護しなければならない。

メールセキュリティを強化し、組織をサイバーセキュリティを改善する進化するサイバー脅威から守る最善の方法を探ろう。

Sunny Yadav

Sunny Yadav

Content Writer

Sunny is a content writer for eSecurity Planet (eSP) with a bachelor’s degree in technology and experience writing for leading cybersecurity brands like Panda Security, Upwind, and Vanta. At eSP, he covers the latest news on cyberattacks, cryptography, data protection, and emerging threats and vulnerabilities. He also explores security policies, governance, and endpoint and mobile security. Sunny enjoys hands-on testing, rigorously evaluating tools to assess their capabilities and real-world performance. He also has extensive experience working with AI tools like ChatGPT and Gemini, experimenting with their applications in cybersecurity, content creation, and research.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.